mirror of
https://github.com/certd/certd.git
synced 2026-07-23 03:27:31 +08:00
Compare commits
10 Commits
b35e7b0702
...
v1.42.0
| Author | SHA1 | Date | |
|---|---|---|---|
| b46948c0ba | |||
| 3024720fc2 | |||
| cf854c9278 | |||
| 608cc2a81f | |||
| 396670dc8f | |||
| 79f65868ca | |||
| 56e5524a0f | |||
| 1ae185d0bc | |||
| 82276b53a8 | |||
| d5882f16be |
@@ -102,7 +102,7 @@ Certd 是可私有化部署的 SSL/TLS 证书自动化管理平台,提供 Web
|
||||
- 只有需要事务传播时才定义 `ctx`;普通查询、纯函数和简单私有方法继续使用明确参数。
|
||||
- 需要按事务上下文取 Repository 时,用 `BaseService.getRepo(ctx, EntityClass)`。
|
||||
- 需要“有事务则复用、无事务则开启”时,用 `BaseService.transactionWithCtx(ctx, callback)`。
|
||||
- 拼接可选 `projectId` 查询条件时,用 `BaseService.buildUserProjectQuery(userId, projectId)`;不要直接写 `{ userId, projectId }`。
|
||||
- 拼接可选 `projectId` 查询条件时,**必须**使用 `BaseService.buildUserProjectQuery(userId, projectId)`,禁止直接写 `{ userId, projectId }`。因为 `projectId` 可能为 `null`/`undefined`,直接放入查询会生成错误的 `WHERE projectId = NULL` 条件。
|
||||
- `ctx` 类型复用 `BaseService` 导出的 `ServiceContext`。
|
||||
- 新增 service 方法避免与 `BaseService` 方法签名冲突,例如不要用 `delete(id)` 覆盖 `delete(ids, where?)`;改用 `deleteById` 等具体名称。
|
||||
|
||||
|
||||
@@ -3,6 +3,34 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* 修复jdk证书格式的问题 ([260f5ae](https://github.com/certd/certd/commit/260f5ae777b83493b0c578fe30fd00ec0c873226))
|
||||
* 修复telegram - 符号转义问题 ([d5882f1](https://github.com/certd/certd/commit/d5882f16bedb09baf09ace92049b02872620f5dc))
|
||||
* **aliyun:** 修复阿里云CDN/DCDN根据证书自动匹配不到证书的bug ([1ae185d](https://github.com/certd/certd/commit/1ae185d0bc356f4678bc38ca0582ce3396f82ebe))
|
||||
|
||||
### Features
|
||||
|
||||
* 通过插件配置懒加载依赖,动态加载第三方依赖包,精简安装镜像大小 ([01568ca](https://github.com/certd/certd/commit/01568ca1489069046b5a89ebdd4ced2f7f6ddf93))
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 阿里云ESA证书部署支持SaaS模式 ([82276b5](https://github.com/certd/certd/commit/82276b53a8474a18a3d0237050907c994fc748f0))
|
||||
* 【破坏性更新】 证书压缩包不再生成文件存储,而是实时打包下载,证书申请插件不再输出certZip ([7cff1a9](https://github.com/certd/certd/commit/7cff1a98424120585205889874b3ef4956a30583))
|
||||
* 火山引擎点播插件支持部署到自定义源站域名 ([095791c](https://github.com/certd/certd/commit/095791cdc2b7c1f4b913b634643afec5e30fe9b0))
|
||||
* 基础镜像改成node:22-trixie-slim,对网络兼容性更好 ([c66a2bd](https://github.com/certd/certd/commit/c66a2bd77ab6dbb3e3fe2c00562b66287a9429ea))
|
||||
* 新增橙域网络(asia-isp) CDN证书部署插件 ([b48831e](https://github.com/certd/certd/commit/b48831e60b0059bef7ef9a34ab61c9dd2f684641))
|
||||
* 优化阿里云API网关增加翻页查询 ([ed58ae3](https://github.com/certd/certd/commit/ed58ae3c5339e4a0238a92acfe7ea6d2f566ea28))
|
||||
* 优化用户体验,首次访问时弹出邮箱账号绑定用以初始化账号 ([608cc2a](https://github.com/certd/certd/commit/608cc2a81ff0b4872c9fe11ed9c9c0b4b90a12a3))
|
||||
* 优化ACME账号字段的选择提示 ([bfd3cac](https://github.com/certd/certd/commit/bfd3cacc687fc5cbc3cb2ca3cadbc140de300dc2))
|
||||
* 支持全自动匹配部署宝塔网站证书 ([4dff48e](https://github.com/certd/certd/commit/4dff48e807c32a7623ec9206cf39c88e88f89f6a))
|
||||
* **cert-plugin:** 调整更新天数自动减半逻辑,仅7天ip证书生效,其他情况下不减半 ([56e5524](https://github.com/certd/certd/commit/56e5524a0f4af3645d70bc3b3ec750b45ba8de10))
|
||||
* dns默认ipv4first ([194463b](https://github.com/certd/certd/commit/194463bea9e797315aa7a724f4b2930701570419))
|
||||
* **passkey:** passkey支持多域名rpid ([79f6586](https://github.com/certd/certd/commit/79f65868ca0f5162bbc2f935ce89abc28011d816))
|
||||
* **plugin:** 在线插件编辑支持配置第三方依赖和插件依赖 ([635f069](https://github.com/certd/certd/commit/635f069012d4193cfb7cb051c96e28eec1247ca2))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# 任务插件
|
||||
共 `133` 款任务插件
|
||||
共 `134` 款任务插件
|
||||
## 1. 证书申请
|
||||
|
||||
| 序号 | 名称 | 说明 |
|
||||
@@ -63,22 +63,23 @@
|
||||
| 7.| **1Panel-部署面板证书** | 更新1Panel的面板证书 |
|
||||
| 8.| **1Panel-更新站点证书** | 更新1Panel的站点证书 |
|
||||
| 9.| **宝塔-删除过期证书** | 删除证书夹中过期证书 |
|
||||
| 10.| **宝塔-WAF证书部署** | 部署宝塔云WAF/aaWAF |
|
||||
| 11.| **宝塔-面板证书部署** | 部署宝塔面板本身的ssl证书 |
|
||||
| 12.| **宝塔win-网站证书部署** | 部署到Windows版宝塔管理的站点的ssl证书 |
|
||||
| 13.| **宝塔-网站证书部署** | 部署宝塔管理的站点的ssl证书,目前支持宝塔网站站点、docker站点等。本插件也支持aaPanel。 |
|
||||
| 14.| **K8S-Apply自定义yaml** | apply自定义yaml到k8s |
|
||||
| 15.| **K8S-Ingress 证书部署** | 部署证书到k8s的Ingress |
|
||||
| 16.| **K8S-部署证书到Secret** | 部署证书到k8s的secret |
|
||||
| 17.| **lucky-更新Lucky证书** | |
|
||||
| 18.| **Plesk-部署Plesk网站证书** | |
|
||||
| 19.| **Plesk-更新证书** | 不会创建新证书记录,直接更新旧的证书 |
|
||||
| 20.| **雷池-更新证书(支持控制台和防护应用)** | 更新长亭雷池WAF的证书,支持更新控制台和防护应用的证书。 |
|
||||
| 21.| **群晖-部署证书到群晖面板** | Synology,支持6.x以上版本 |
|
||||
| 22.| **群晖-刷新OTP登录有效期** | 群晖登录状态可能30天失效,需要在失效之前登录一次,刷新有效期,您可以将其放在“部署到群晖面板”任务之后 |
|
||||
| 23.| **uniCloud-部署到服务空间** | 部署到服务空间 |
|
||||
| 24.| **Proxmox-上传证书到Proxmox** | |
|
||||
| 25.| **威联通-部署证书到威联通** | 部署证书到qnap |
|
||||
| 10.| **宝塔-全自动部署** | 根据证书域名自动匹配宝塔站点,全自动部署SSL证书。新增加速域名自动感知,自动新增部署 |
|
||||
| 11.| **宝塔-WAF证书部署** | 部署宝塔云WAF/aaWAF |
|
||||
| 12.| **宝塔-面板证书部署** | 部署宝塔面板本身的ssl证书 |
|
||||
| 13.| **宝塔win-网站证书部署** | 部署到Windows版宝塔管理的站点的ssl证书 |
|
||||
| 14.| **宝塔-网站证书部署** | 部署宝塔管理的站点的ssl证书,目前支持宝塔网站站点、docker站点等。本插件也支持aaPanel。 |
|
||||
| 15.| **K8S-Apply自定义yaml** | apply自定义yaml到k8s |
|
||||
| 16.| **K8S-Ingress 证书部署** | 部署证书到k8s的Ingress |
|
||||
| 17.| **K8S-部署证书到Secret** | 部署证书到k8s的secret |
|
||||
| 18.| **lucky-更新Lucky证书** | |
|
||||
| 19.| **Plesk-部署Plesk网站证书** | |
|
||||
| 20.| **Plesk-更新证书** | 不会创建新证书记录,直接更新旧的证书 |
|
||||
| 21.| **雷池-更新证书(支持控制台和防护应用)** | 更新长亭雷池WAF的证书,支持更新控制台和防护应用的证书。 |
|
||||
| 22.| **群晖-部署证书到群晖面板** | Synology,支持6.x以上版本 |
|
||||
| 23.| **群晖-刷新OTP登录有效期** | 群晖登录状态可能30天失效,需要在失效之前登录一次,刷新有效期,您可以将其放在“部署到群晖面板”任务之后 |
|
||||
| 24.| **uniCloud-部署到服务空间** | 部署到服务空间 |
|
||||
| 25.| **Proxmox-上传证书到Proxmox** | |
|
||||
| 26.| **威联通-部署证书到威联通** | 部署证书到qnap |
|
||||
## 5. 阿里云
|
||||
|
||||
| 序号 | 名称 | 说明 |
|
||||
@@ -91,7 +92,7 @@
|
||||
| 6.| **阿里云-部署证书至API网关** | 自动部署域名证书至阿里云API网关(APIGateway) |
|
||||
| 7.| **阿里云-部署证书至CDN** | 自动部署域名证书至阿里云CDN |
|
||||
| 8.| **阿里云-部署证书至DCDN** | 依赖证书申请前置任务,自动部署域名证书至阿里云DCDN |
|
||||
| 9.| **阿里云-部署至ESA** | 部署证书到阿里云ESA(边缘安全加速),自动删除过期证书 |
|
||||
| 9.| **阿里云-部署至ESA** | 部署证书到阿里云ESA(边缘安全加速),支持边缘证书和SaaS证书两种模式 |
|
||||
| 10.| **阿里云-部署至阿里云FC(3.0)** | 部署证书到阿里云函数计算(FC3.0) |
|
||||
| 11.| **阿里云-部署至GA** | 部署证书到阿里云GA(全球加速),支持更新默认证书和扩展证书 |
|
||||
| 12.| **阿里云-部署至直播(Live)** | 部署证书到阿里云视频直播(Live)域名 |
|
||||
|
||||
+1
-1
@@ -9,5 +9,5 @@
|
||||
}
|
||||
},
|
||||
"npmClient": "pnpm",
|
||||
"version": "1.41.4"
|
||||
"version": "1.42.0"
|
||||
}
|
||||
|
||||
@@ -3,6 +3,12 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/publishlab/node-acme-client/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 新增橙域网络(asia-isp) CDN证书部署插件 ([b48831e](https://github.com/publishlab/node-acme-client/commit/b48831e60b0059bef7ef9a34ab61c9dd2f684641))
|
||||
|
||||
## [1.41.4](https://github.com/publishlab/node-acme-client/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/acme-client
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
"description": "Simple and unopinionated ACME client",
|
||||
"private": false,
|
||||
"author": "nmorsman",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"module": "./dist/index.js",
|
||||
"main": "./dist/index.js",
|
||||
@@ -18,7 +18,7 @@
|
||||
"types"
|
||||
],
|
||||
"dependencies": {
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@peculiar/x509": "^1.11.0",
|
||||
"asn1js": "^3.0.5",
|
||||
"axios": "^1.9.0",
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/basic
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1 +1 @@
|
||||
21:25
|
||||
19:21
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/basic",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"module": "./dist/index.js",
|
||||
|
||||
@@ -3,6 +3,12 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Features
|
||||
|
||||
* 通过插件配置懒加载依赖,动态加载第三方依赖包,精简安装镜像大小 ([01568ca](https://github.com/certd/certd/commit/01568ca1489069046b5a89ebdd4ced2f7f6ddf93))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/pipeline
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/pipeline",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"module": "./dist/index.js",
|
||||
@@ -21,8 +21,8 @@
|
||||
"lint": "eslint --fix"
|
||||
},
|
||||
"dependencies": {
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/plus-core": "^1.41.4",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@certd/plus-core": "^1.42.0",
|
||||
"dayjs": "^1.11.7",
|
||||
"lodash-es": "^4.17.21",
|
||||
"reflect-metadata": "^0.2.2"
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/lib-huawei
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/lib-huawei",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"main": "./dist/bundle.js",
|
||||
"module": "./dist/bundle.js",
|
||||
"types": "./dist/d/index.d.ts",
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/lib-iframe
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/lib-iframe",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"module": "./dist/index.js",
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/jdcloud
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@certd/jdcloud",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"description": "jdcloud openApi sdk",
|
||||
"main": "./dist/bundle.js",
|
||||
"module": "./dist/bundle.js",
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/lib-k8s
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/lib-k8s
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/lib-k8s",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"module": "./dist/index.js",
|
||||
@@ -21,7 +21,7 @@
|
||||
"lint": "eslint --fix"
|
||||
},
|
||||
"dependencies": {
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@kubernetes/client-node": "0.21.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
|
||||
@@ -3,6 +3,19 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Features
|
||||
|
||||
* 通过插件配置懒加载依赖,动态加载第三方依赖包,精简安装镜像大小 ([01568ca](https://github.com/certd/certd/commit/01568ca1489069046b5a89ebdd4ced2f7f6ddf93))
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 【破坏性更新】 证书压缩包不再生成文件存储,而是实时打包下载,证书申请插件不再输出certZip ([7cff1a9](https://github.com/certd/certd/commit/7cff1a98424120585205889874b3ef4956a30583))
|
||||
* 优化用户体验,首次访问时弹出邮箱账号绑定用以初始化账号 ([608cc2a](https://github.com/certd/certd/commit/608cc2a81ff0b4872c9fe11ed9c9c0b4b90a12a3))
|
||||
* 支持全自动匹配部署宝塔网站证书 ([4dff48e](https://github.com/certd/certd/commit/4dff48e807c32a7623ec9206cf39c88e88f89f6a))
|
||||
* dns默认ipv4first ([194463b](https://github.com/certd/certd/commit/194463bea9e797315aa7a724f4b2930701570419))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/lib-server
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@certd/lib-server",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"description": "midway with flyway, sql upgrade way ",
|
||||
"private": false,
|
||||
"type": "module",
|
||||
@@ -29,11 +29,11 @@
|
||||
],
|
||||
"license": "AGPL",
|
||||
"dependencies": {
|
||||
"@certd/acme-client": "^1.41.4",
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/pipeline": "^1.41.4",
|
||||
"@certd/plugin-lib": "^1.41.4",
|
||||
"@certd/plus-core": "^1.41.4",
|
||||
"@certd/acme-client": "^1.42.0",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@certd/pipeline": "^1.42.0",
|
||||
"@certd/plugin-lib": "^1.42.0",
|
||||
"@certd/plus-core": "^1.42.0",
|
||||
"@midwayjs/cache": "3.14.0",
|
||||
"@midwayjs/core": "3.20.11",
|
||||
"@midwayjs/i18n": "3.20.13",
|
||||
@@ -49,8 +49,6 @@
|
||||
"typeorm": "^0.3.20"
|
||||
},
|
||||
"devDependencies": {
|
||||
"mwts": "^1.3.0",
|
||||
"mwtsc": "^1.4.0",
|
||||
"@types/chai": "^4.3.12",
|
||||
"@types/mocha": "^10.0.6",
|
||||
"@types/node": "^18",
|
||||
@@ -62,6 +60,8 @@
|
||||
"eslint-plugin-prettier": "^5.1.3",
|
||||
"esmock": "^2.7.5",
|
||||
"mocha": "^10.6.0",
|
||||
"mwts": "^1.3.0",
|
||||
"mwtsc": "^1.4.0",
|
||||
"prettier": "3.3.3",
|
||||
"rimraf": "^5.0.5",
|
||||
"ts-node": "^10.9.2",
|
||||
|
||||
@@ -1,9 +1,8 @@
|
||||
import { ApplicationContext, Inject } from '@midwayjs/core';
|
||||
import type {IMidwayContainer} from '@midwayjs/core';
|
||||
import * as koa from '@midwayjs/koa';
|
||||
import { Constants } from './constants.js';
|
||||
import { isEnterprise } from './mode.js';
|
||||
|
||||
import { ApplicationContext, Inject } from "@midwayjs/core";
|
||||
import type { IMidwayContainer } from "@midwayjs/core";
|
||||
import * as koa from "@midwayjs/koa";
|
||||
import { Constants } from "./constants.js";
|
||||
import { isEnterprise } from "./mode.js";
|
||||
|
||||
export abstract class BaseController {
|
||||
@Inject()
|
||||
@@ -41,7 +40,7 @@ export abstract class BaseController {
|
||||
getUserId() {
|
||||
const userId = this.ctx.user?.id;
|
||||
if (userId == null) {
|
||||
throw new Error('Token已过期');
|
||||
throw new Error("Token已过期");
|
||||
}
|
||||
return userId;
|
||||
}
|
||||
@@ -49,7 +48,7 @@ export abstract class BaseController {
|
||||
getLoginUser() {
|
||||
const user = this.ctx.user;
|
||||
if (user == null) {
|
||||
throw new Error('Token已过期');
|
||||
throw new Error("Token已过期");
|
||||
}
|
||||
return user;
|
||||
}
|
||||
@@ -61,73 +60,71 @@ export abstract class BaseController {
|
||||
}
|
||||
}
|
||||
|
||||
async getProjectId(permission:string) {
|
||||
async getProjectId(permission: string) {
|
||||
if (!isEnterprise()) {
|
||||
return undefined
|
||||
return undefined;
|
||||
}
|
||||
let projectIdStr = this.ctx.headers["project-id"] as string;
|
||||
if (!projectIdStr){
|
||||
if (!projectIdStr) {
|
||||
projectIdStr = this.ctx.request.query["projectId"] as string;
|
||||
}
|
||||
if (!projectIdStr) {
|
||||
//这里必须抛异常,否则可能会有权限问题
|
||||
throw new Error("projectId 不能为空")
|
||||
throw new Error("projectId 不能为空");
|
||||
}
|
||||
const userId = this.getUserId()
|
||||
const projectId = parseInt(projectIdStr)
|
||||
await this.checkProjectPermission(userId, projectId,permission)
|
||||
const userId = this.getUserId();
|
||||
const projectId = parseInt(projectIdStr);
|
||||
await this.checkProjectPermission(userId, projectId, permission);
|
||||
return projectId;
|
||||
}
|
||||
|
||||
async getProjectUserId(permission:string){
|
||||
let userId = this.getUserId()
|
||||
const projectId = await this.getProjectId(permission)
|
||||
if(projectId){
|
||||
userId = -1 // 企业管理模式下,用户id固定-1
|
||||
async getProjectUserId(permission: string) {
|
||||
let userId = this.getUserId();
|
||||
const projectId = await this.getProjectId(permission);
|
||||
if (projectId) {
|
||||
userId = -1; // 企业管理模式下,用户id固定-1
|
||||
}
|
||||
return {
|
||||
projectId,userId
|
||||
}
|
||||
projectId,
|
||||
userId,
|
||||
};
|
||||
}
|
||||
async getProjectUserIdRead(){
|
||||
return await this.getProjectUserId("read")
|
||||
async getProjectUserIdRead() {
|
||||
return await this.getProjectUserId("read");
|
||||
}
|
||||
async getProjectUserIdWrite(){
|
||||
return await this.getProjectUserId("write")
|
||||
async getProjectUserIdWrite() {
|
||||
return await this.getProjectUserId("write");
|
||||
}
|
||||
async getProjectUserIdAdmin(){
|
||||
return await this.getProjectUserId("admin")
|
||||
async getProjectUserIdAdmin() {
|
||||
return await this.getProjectUserId("admin");
|
||||
}
|
||||
|
||||
async checkProjectPermission(userId: number, projectId: number,permission:string) {
|
||||
const projectService:any = await this.applicationContext.getAsync("projectService");
|
||||
await projectService.checkPermission({userId,projectId,permission})
|
||||
async checkProjectPermission(userId: number, projectId: number, permission: string) {
|
||||
const projectService: any = await this.applicationContext.getAsync("projectService");
|
||||
await projectService.checkPermission({ userId, projectId, permission });
|
||||
}
|
||||
|
||||
/**
|
||||
*
|
||||
*
|
||||
* @param service 检查记录是否属于某用户或某项目
|
||||
* @param id
|
||||
* @param id
|
||||
*/
|
||||
async checkOwner(service:any,id:number,permission:string,allowAdmin:boolean = false){
|
||||
let { projectId,userId } = await this.getProjectUserId(permission)
|
||||
const authService:any = await this.applicationContext.getAsync("authService");
|
||||
async checkOwner(service: any, id: number, permission: string, allowAdmin: boolean = false) {
|
||||
const { projectId, userId } = await this.getProjectUserId(permission);
|
||||
const authService: any = await this.applicationContext.getAsync("authService");
|
||||
if (projectId) {
|
||||
await authService.checkProjectId(service, id, projectId);
|
||||
}else{
|
||||
|
||||
if(userId === Constants.systemUserId){
|
||||
} else {
|
||||
if (userId === Constants.systemUserId) {
|
||||
//系统级别,不检查权限
|
||||
}else{
|
||||
if(allowAdmin){
|
||||
} else {
|
||||
if (allowAdmin) {
|
||||
await authService.checkUserIdButAllowAdmin(this.ctx, service, id);
|
||||
}else{
|
||||
await authService.checkUserId( service, id, userId);
|
||||
} else {
|
||||
await authService.checkUserId(service, id, userId);
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
return {projectId,userId}
|
||||
return { projectId, userId };
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -56,7 +56,7 @@ export abstract class BaseService<T> {
|
||||
return dataSource.getRepository(entity);
|
||||
}
|
||||
|
||||
protected buildUserProjectQuery(userId: number, projectId?: number) {
|
||||
public buildUserProjectQuery(userId: number, projectId?: number) {
|
||||
const query: { userId: number; projectId?: number; [key: string]: any } = {
|
||||
userId,
|
||||
};
|
||||
|
||||
@@ -1,33 +1,33 @@
|
||||
import { Column, Entity, PrimaryGeneratedColumn } from 'typeorm';
|
||||
import { Column, Entity, PrimaryGeneratedColumn } from "typeorm";
|
||||
|
||||
/**
|
||||
*/
|
||||
@Entity('sys_settings')
|
||||
@Entity("sys_settings")
|
||||
export class SysSettingsEntity {
|
||||
@PrimaryGeneratedColumn()
|
||||
id: number;
|
||||
@Column({ comment: 'key', length: 100 })
|
||||
@Column({ comment: "key", length: 100 })
|
||||
key: string;
|
||||
@Column({ comment: '名称', length: 100 })
|
||||
@Column({ comment: "名称", length: 100 })
|
||||
title: string;
|
||||
|
||||
@Column({ name: 'setting', comment: '设置', length: 1024, nullable: true })
|
||||
@Column({ name: "setting", comment: "设置", length: 1024, nullable: true })
|
||||
setting: string;
|
||||
|
||||
// public 公开读,私有写, private 私有读,私有写
|
||||
@Column({ name: 'access', comment: '访问权限' })
|
||||
@Column({ name: "access", comment: "访问权限" })
|
||||
access: string;
|
||||
|
||||
@Column({
|
||||
name: 'create_time',
|
||||
comment: '创建时间',
|
||||
default: () => 'CURRENT_TIMESTAMP',
|
||||
name: "create_time",
|
||||
comment: "创建时间",
|
||||
default: () => "CURRENT_TIMESTAMP",
|
||||
})
|
||||
createTime: Date;
|
||||
@Column({
|
||||
name: 'update_time',
|
||||
comment: '修改时间',
|
||||
default: () => 'CURRENT_TIMESTAMP',
|
||||
name: "update_time",
|
||||
comment: "修改时间",
|
||||
default: () => "CURRENT_TIMESTAMP",
|
||||
})
|
||||
updateTime: Date;
|
||||
}
|
||||
|
||||
@@ -1,19 +1,19 @@
|
||||
import { cloneDeep } from 'lodash-es';
|
||||
import { cloneDeep } from "lodash-es";
|
||||
|
||||
export class BaseSettings {
|
||||
static __key__: string;
|
||||
static __title__: string;
|
||||
static __access__ = 'private';
|
||||
static __access__ = "private";
|
||||
|
||||
static getCacheKey() {
|
||||
return 'settings.' + this.__key__;
|
||||
return "settings." + this.__key__;
|
||||
}
|
||||
}
|
||||
|
||||
export class SysPublicSettings extends BaseSettings {
|
||||
static __key__ = 'sys.public';
|
||||
static __title__ = '系统公共设置';
|
||||
static __access__ = 'public';
|
||||
static __key__ = "sys.public";
|
||||
static __title__ = "系统公共设置";
|
||||
static __access__ = "public";
|
||||
|
||||
registerEnabled = false;
|
||||
userValidTimeEnabled?: boolean = false;
|
||||
@@ -34,19 +34,15 @@ export class SysPublicSettings extends BaseSettings {
|
||||
aiChatEnabled = true;
|
||||
homePageEnabled = true;
|
||||
|
||||
|
||||
//验证码是否开启
|
||||
captchaEnabled = false;
|
||||
//验证码类型
|
||||
captchaType?: string;
|
||||
captchaAddonId?: number;
|
||||
|
||||
|
||||
|
||||
//流水线是否启用有效期
|
||||
pipelineValidTimeEnabled?: boolean = false;
|
||||
|
||||
|
||||
//证书域名添加到监控
|
||||
certDomainAddToMonitorEnabled?: boolean = false;
|
||||
|
||||
@@ -60,12 +56,15 @@ export class SysPublicSettings extends BaseSettings {
|
||||
|
||||
// 第三方OAuth配置
|
||||
oauthEnabled?: boolean = false;
|
||||
oauthProviders: Record<string, {
|
||||
type: string;
|
||||
title: string;
|
||||
addonId: number;
|
||||
icon?: string;
|
||||
}> = {};
|
||||
oauthProviders: Record<
|
||||
string,
|
||||
{
|
||||
type: string;
|
||||
title: string;
|
||||
addonId: number;
|
||||
icon?: string;
|
||||
}
|
||||
> = {};
|
||||
|
||||
notice?: string;
|
||||
|
||||
@@ -73,40 +72,37 @@ export class SysPublicSettings extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysPrivateSettings extends BaseSettings {
|
||||
static __title__ = '系统私有设置';
|
||||
static __access__ = 'private';
|
||||
static __key__ = 'sys.private';
|
||||
static __title__ = "系统私有设置";
|
||||
static __access__ = "private";
|
||||
static __key__ = "sys.private";
|
||||
jwtKey?: string;
|
||||
encryptSecret?: string;
|
||||
|
||||
httpsProxy? = '';
|
||||
httpProxy? = '';
|
||||
noProxy? = '';
|
||||
commonHeaders?: string = '';
|
||||
httpsProxy? = "";
|
||||
httpProxy? = "";
|
||||
noProxy? = "";
|
||||
commonHeaders?: string = "";
|
||||
|
||||
reverseProxies?: Record<string, string> = {};
|
||||
|
||||
dnsResultOrder? = '';
|
||||
dnsResultOrder? = "";
|
||||
commonCnameEnabled?: boolean = true;
|
||||
|
||||
httpRequestTimeout?: number = 30;
|
||||
|
||||
pipelineMaxRunningCount?: number;
|
||||
|
||||
|
||||
environmentVars?: string = '';
|
||||
|
||||
environmentVars?: string = "";
|
||||
|
||||
acmeWalkFromAuthoritative?: boolean = true;
|
||||
|
||||
|
||||
sms?: {
|
||||
type?: string;
|
||||
config?: any;
|
||||
} = {
|
||||
type: 'aliyun',
|
||||
config: {},
|
||||
};
|
||||
type: "aliyun",
|
||||
config: {},
|
||||
};
|
||||
|
||||
removeSecret() {
|
||||
const clone = cloneDeep(this);
|
||||
@@ -117,9 +113,9 @@ export class SysPrivateSettings extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysInstallInfo extends BaseSettings {
|
||||
static __title__ = '系统安装信息';
|
||||
static __key__ = 'sys.install';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "系统安装信息";
|
||||
static __key__ = "sys.install";
|
||||
static __access__ = "private";
|
||||
installTime?: number;
|
||||
siteId?: string;
|
||||
bindUserId?: number;
|
||||
@@ -130,21 +126,20 @@ export class SysInstallInfo extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysLicenseInfo extends BaseSettings {
|
||||
static __title__ = '授权许可信息';
|
||||
static __key__ = 'sys.license';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "授权许可信息";
|
||||
static __key__ = "sys.license";
|
||||
static __access__ = "private";
|
||||
license?: string;
|
||||
}
|
||||
|
||||
|
||||
export type EmailTemplate = {
|
||||
addonId?: number;
|
||||
}
|
||||
};
|
||||
|
||||
export class SysEmailConf extends BaseSettings {
|
||||
static __title__ = '邮箱配置';
|
||||
static __key__ = 'sys.email';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "邮箱配置";
|
||||
static __key__ = "sys.email";
|
||||
static __access__ = "private";
|
||||
|
||||
host: string;
|
||||
port: number;
|
||||
@@ -160,18 +155,18 @@ export class SysEmailConf extends BaseSettings {
|
||||
sender: string;
|
||||
usePlus?: boolean;
|
||||
|
||||
templates:{
|
||||
registerCode?: EmailTemplate,
|
||||
forgotPassword?: EmailTemplate,
|
||||
pipelineResult?: EmailTemplate,
|
||||
common?: EmailTemplate,
|
||||
}
|
||||
templates: {
|
||||
registerCode?: EmailTemplate;
|
||||
forgotPassword?: EmailTemplate;
|
||||
pipelineResult?: EmailTemplate;
|
||||
common?: EmailTemplate;
|
||||
};
|
||||
}
|
||||
|
||||
export class SysSiteInfo extends BaseSettings {
|
||||
static __title__ = '站点信息';
|
||||
static __key__ = 'sys.site';
|
||||
static __access__ = 'public';
|
||||
static __title__ = "站点信息";
|
||||
static __key__ = "sys.site";
|
||||
static __access__ = "public";
|
||||
title?: string;
|
||||
slogan?: string;
|
||||
logo?: string;
|
||||
@@ -179,9 +174,9 @@ export class SysSiteInfo extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysSecretBackup extends BaseSettings {
|
||||
static __title__ = '密钥信息备份';
|
||||
static __key__ = 'sys.secret.backup';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "密钥信息备份";
|
||||
static __key__ = "sys.secret.backup";
|
||||
static __access__ = "private";
|
||||
siteId?: string;
|
||||
encryptSecret?: string;
|
||||
}
|
||||
@@ -190,9 +185,9 @@ export class SysSecretBackup extends BaseSettings {
|
||||
* 不要修改
|
||||
*/
|
||||
export class SysSecret extends BaseSettings {
|
||||
static __title__ = '密钥信息';
|
||||
static __key__ = 'sys.secret';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "密钥信息";
|
||||
static __key__ = "sys.secret";
|
||||
static __access__ = "private";
|
||||
siteId?: string;
|
||||
encryptSecret?: string;
|
||||
}
|
||||
@@ -215,9 +210,9 @@ export type MenuItem = {
|
||||
children?: MenuItem[];
|
||||
};
|
||||
export class SysHeaderMenus extends BaseSettings {
|
||||
static __title__ = '顶部菜单';
|
||||
static __key__ = 'sys.header.menus';
|
||||
static __access__ = 'public';
|
||||
static __title__ = "顶部菜单";
|
||||
static __key__ = "sys.header.menus";
|
||||
static __access__ = "public";
|
||||
|
||||
menus: MenuItem[];
|
||||
}
|
||||
@@ -228,9 +223,9 @@ export type PaymentItem = {
|
||||
};
|
||||
|
||||
export class SysPaymentSetting extends BaseSettings {
|
||||
static __title__ = '支付设置';
|
||||
static __key__ = 'sys.payment';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "支付设置";
|
||||
static __key__ = "sys.payment";
|
||||
static __access__ = "private";
|
||||
|
||||
yizhifu?: PaymentItem = { enabled: false };
|
||||
|
||||
@@ -240,9 +235,9 @@ export class SysPaymentSetting extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysSuiteSetting extends BaseSettings {
|
||||
static __title__ = '套餐设置';
|
||||
static __key__ = 'sys.suite';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "套餐设置";
|
||||
static __key__ = "sys.suite";
|
||||
static __access__ = "private";
|
||||
|
||||
enabled: boolean = false;
|
||||
|
||||
@@ -257,26 +252,25 @@ export class SysSuiteSetting extends BaseSettings {
|
||||
}
|
||||
|
||||
export class SysAutoFixSetting extends BaseSettings {
|
||||
static __title__ = '自动修复记录';
|
||||
static __key__ = 'sys.auto.fix';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "自动修复记录";
|
||||
static __key__ = "sys.auto.fix";
|
||||
static __access__ = "private";
|
||||
|
||||
fixed: Record<string, boolean> = {};
|
||||
}
|
||||
|
||||
|
||||
export type SiteHidden = {
|
||||
enabled: boolean;
|
||||
openPath?: string;
|
||||
//md5 hash 两次后保存
|
||||
openPassword?: string;
|
||||
autoHiddenTimes?: number;
|
||||
hiddenOpenApi?: boolean
|
||||
hiddenOpenApi?: boolean;
|
||||
};
|
||||
export class SysSafeSetting extends BaseSettings {
|
||||
static __title__ = '站点安全设置';
|
||||
static __key__ = 'sys.safe';
|
||||
static __access__ = 'private';
|
||||
static __title__ = "站点安全设置";
|
||||
static __key__ = "sys.safe";
|
||||
static __access__ = "private";
|
||||
|
||||
// 站点隐藏
|
||||
hidden: SiteHidden = {
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/midway-flyway-js
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@certd/midway-flyway-js",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"description": "midway with flyway, sql upgrade way ",
|
||||
"private": false,
|
||||
"type": "module",
|
||||
|
||||
@@ -3,6 +3,10 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
**Note:** Version bump only for package @certd/plugin-cert
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/plugin-cert
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/plugin-cert",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"types": "./dist/index.d.ts",
|
||||
@@ -20,7 +20,7 @@
|
||||
"lint": "eslint --fix"
|
||||
},
|
||||
"dependencies": {
|
||||
"@certd/plugin-lib": "^1.41.4"
|
||||
"@certd/plugin-lib": "^1.42.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/chai": "^4.3.12",
|
||||
|
||||
@@ -3,6 +3,21 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* 修复jdk证书格式的问题 ([260f5ae](https://github.com/certd/certd/commit/260f5ae777b83493b0c578fe30fd00ec0c873226))
|
||||
|
||||
### Features
|
||||
|
||||
* 通过插件配置懒加载依赖,动态加载第三方依赖包,精简安装镜像大小 ([01568ca](https://github.com/certd/certd/commit/01568ca1489069046b5a89ebdd4ced2f7f6ddf93))
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 【破坏性更新】 证书压缩包不再生成文件存储,而是实时打包下载,证书申请插件不再输出certZip ([7cff1a9](https://github.com/certd/certd/commit/7cff1a98424120585205889874b3ef4956a30583))
|
||||
* 新增橙域网络(asia-isp) CDN证书部署插件 ([b48831e](https://github.com/certd/certd/commit/b48831e60b0059bef7ef9a34ab61c9dd2f684641))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
**Note:** Version bump only for package @certd/plugin-lib
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@certd/plugin-lib",
|
||||
"private": false,
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"type": "module",
|
||||
"main": "./dist/index.js",
|
||||
"types": "./dist/index.d.ts",
|
||||
@@ -17,9 +17,9 @@
|
||||
"lint": "eslint --fix"
|
||||
},
|
||||
"dependencies": {
|
||||
"@certd/acme-client": "^1.41.4",
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/pipeline": "^1.41.4",
|
||||
"@certd/acme-client": "^1.42.0",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@certd/pipeline": "^1.42.0",
|
||||
"dayjs": "^1.11.7",
|
||||
"jszip": "^3.10.1",
|
||||
"lodash-es": "^4.17.21",
|
||||
@@ -27,7 +27,6 @@
|
||||
"punycode.js": "^2.3.1"
|
||||
},
|
||||
"devDependencies": {
|
||||
"rimraf": "^5.0.5",
|
||||
"@types/chai": "^4.3.12",
|
||||
"@types/mocha": "^10.0.6",
|
||||
"@typescript-eslint/eslint-plugin": "^8.26.1",
|
||||
@@ -41,6 +40,7 @@
|
||||
"mocha": "^10.6.0",
|
||||
"node-forge": "^1.3.1",
|
||||
"prettier": "3.3.3",
|
||||
"rimraf": "^5.0.5",
|
||||
"ts-node": "^10.9.2",
|
||||
"tslib": "^2.8.1",
|
||||
"typescript": "^5.4.2"
|
||||
|
||||
@@ -3,6 +3,15 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 【破坏性更新】 证书压缩包不再生成文件存储,而是实时打包下载,证书申请插件不再输出certZip ([7cff1a9](https://github.com/certd/certd/commit/7cff1a98424120585205889874b3ef4956a30583))
|
||||
* 优化用户体验,首次访问时弹出邮箱账号绑定用以初始化账号 ([608cc2a](https://github.com/certd/certd/commit/608cc2a81ff0b4872c9fe11ed9c9c0b4b90a12a3))
|
||||
* **passkey:** passkey支持多域名rpid ([79f6586](https://github.com/certd/certd/commit/79f65868ca0f5162bbc2f935ce89abc28011d816))
|
||||
* **plugin:** 在线插件编辑支持配置第三方依赖和插件依赖 ([635f069](https://github.com/certd/certd/commit/635f069012d4193cfb7cb051c96e28eec1247ca2))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@certd/ui-client",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"dev": "vite --open",
|
||||
@@ -105,8 +105,8 @@
|
||||
"zod-defaults": "^0.1.3"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@certd/lib-iframe": "^1.41.4",
|
||||
"@certd/pipeline": "^1.41.4",
|
||||
"@certd/lib-iframe": "^1.42.0",
|
||||
"@certd/pipeline": "^1.42.0",
|
||||
"@rollup/plugin-commonjs": "^25.0.7",
|
||||
"@rollup/plugin-node-resolve": "^15.2.3",
|
||||
"@types/chai": "^4.3.12",
|
||||
|
||||
@@ -26,9 +26,10 @@ export default {
|
||||
store: "Store",
|
||||
version: "Version",
|
||||
pluginDependencies: "Plugin Dependencies",
|
||||
pluginDependenciesHelper: "Format: [author/]pluginName[:version]. Required plugins must be installed first",
|
||||
pluginDependenciesHelper:
|
||||
"Format: pluginType:pluginName, use * for version\nSupported: plugin:name, access:name, notification:name, dnsProvider:name, addon:subtype:name\nExample: access:AliyunAccess, plugin:DeployToAliyunCDN",
|
||||
thirdPartyDependencies: "Third-party Dependencies",
|
||||
thirdPartyDependenciesHelper: "Format: npmPackageName: version. Auto-installed at runtime",
|
||||
thirdPartyDependenciesHelper: "Format: npmPackageName: version. Auto-installed at runtime\nExample: aliyun-sdk: ^1.0.0",
|
||||
editableRunStrategy: "Editable Run Strategy",
|
||||
editable: "Editable",
|
||||
notEditable: "Not Editable",
|
||||
|
||||
@@ -70,7 +70,7 @@ export default {
|
||||
confirmToggleStatus: "确定要{action}吗?",
|
||||
batchDelete: "批量删除",
|
||||
sourcee: "来源",
|
||||
clickToToggle: "点击切换启用/禁用",
|
||||
clickToToggle: "点击启用/禁用",
|
||||
nickName: "昵称",
|
||||
avatar: "头像",
|
||||
expires: "过期",
|
||||
|
||||
@@ -26,9 +26,9 @@ export default {
|
||||
store: "市场",
|
||||
version: "版本",
|
||||
pluginDependencies: "插件依赖",
|
||||
pluginDependenciesHelper: "格式: [作者/]插件名[:版本],需先安装依赖插件",
|
||||
pluginDependenciesHelper: "格式: 插件类型:插件名,版本号填 *\n支持: plugin:name、access:name、notification:name、dnsProvider:name、addon:subtype:name\n示例: access:AliyunAccess, plugin:DeployToAliyunCDN",
|
||||
thirdPartyDependencies: "第三方依赖",
|
||||
thirdPartyDependenciesHelper: "格式: npm包名: 版本号,运行时自动安装",
|
||||
thirdPartyDependenciesHelper: "格式: npm包名: 版本号,运行时自动安装\n示例: aliyun-sdk: ^1.0.0",
|
||||
editableRunStrategy: "可编辑运行策略",
|
||||
editable: "可编辑",
|
||||
notEditable: "不可编辑",
|
||||
|
||||
@@ -31,6 +31,13 @@ export function useFormDialog() {
|
||||
crudOptions: {
|
||||
columns: req.columns,
|
||||
form: {
|
||||
labelCol: {
|
||||
// @ts-ignore
|
||||
span: null,
|
||||
style: {
|
||||
width: "100px",
|
||||
},
|
||||
},
|
||||
initialForm: req.initialForm,
|
||||
wrapper: warpper,
|
||||
async afterSubmit() {},
|
||||
@@ -44,7 +51,7 @@ export function useFormDialog() {
|
||||
};
|
||||
}
|
||||
const { crudOptions } = createCrudOptions();
|
||||
await openCrudFormDialog({ crudOptions });
|
||||
return await openCrudFormDialog({ crudOptions });
|
||||
}
|
||||
return {
|
||||
openFormDialog,
|
||||
|
||||
@@ -16,8 +16,8 @@
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script>
|
||||
import { defineComponent, reactive, ref, watch, inject } from "vue";
|
||||
<script lang="ts">
|
||||
import { defineComponent, reactive, ref, watch, inject, onMounted } from "vue";
|
||||
import CertAccessModal from "./access/index.vue";
|
||||
import { createAccessApi } from "../api";
|
||||
import { message } from "ant-design-vue";
|
||||
@@ -55,6 +55,10 @@ export default defineComponent({
|
||||
type: Boolean,
|
||||
default: false,
|
||||
},
|
||||
defaultSelect: {
|
||||
type: Boolean,
|
||||
default: false,
|
||||
},
|
||||
},
|
||||
emits: ["update:modelValue", "change", "selectedChange"],
|
||||
setup(props, ctx) {
|
||||
@@ -158,12 +162,43 @@ export default defineComponent({
|
||||
},
|
||||
});
|
||||
|
||||
async function selectFirst(clearCurrent = false) {
|
||||
if (!clearCurrent && props.modelValue) {
|
||||
return;
|
||||
}
|
||||
const searchForm = projectStore.getSearchForm();
|
||||
const query: any = {
|
||||
query: {
|
||||
type: props.type,
|
||||
...searchForm,
|
||||
},
|
||||
page: { page: 1, pageSize: 1 },
|
||||
sort: { prop: "id", order: "ascending" },
|
||||
};
|
||||
if (props.subtype) {
|
||||
query.query.subtype = props.subtype;
|
||||
}
|
||||
const res = await api.GetList(query);
|
||||
const records = res?.records || [];
|
||||
if (records.length > 0) {
|
||||
await emitValue(records[0].id);
|
||||
}
|
||||
}
|
||||
|
||||
onMounted(async () => {
|
||||
if (!props.defaultSelect) {
|
||||
return;
|
||||
}
|
||||
await selectFirst();
|
||||
});
|
||||
|
||||
return {
|
||||
clear,
|
||||
target,
|
||||
selectedId,
|
||||
providerDefine,
|
||||
chooseForm,
|
||||
selectFirst,
|
||||
};
|
||||
},
|
||||
});
|
||||
|
||||
@@ -18,6 +18,10 @@ defineProps<{
|
||||
showButton: boolean;
|
||||
}>();
|
||||
|
||||
const emit = defineEmits<{
|
||||
(e: "close"): void;
|
||||
}>();
|
||||
|
||||
let passwordFormRef = ref();
|
||||
|
||||
type OpenOptions = {
|
||||
@@ -68,8 +72,8 @@ const passwordFormOptions: CrudOptions = {
|
||||
},
|
||||
async afterSubmit() {
|
||||
const formData = passwordFormRef.value?.getFormData?.();
|
||||
const message = formData?.init ? t("authentication.initPasswordSuccessMessage") : t("authentication.successMessage");
|
||||
notification.success({ message });
|
||||
const msg = formData?.init ? t("authentication.initPasswordSuccessMessage") : t("authentication.successMessage");
|
||||
notification.success({ message: msg });
|
||||
},
|
||||
},
|
||||
columns: {
|
||||
@@ -84,6 +88,7 @@ const passwordFormOptions: CrudOptions = {
|
||||
title: t("authentication.oldPassword"),
|
||||
type: "password",
|
||||
form: {
|
||||
//@ts-ignore
|
||||
show: compute(({ form }) => form.init !== true),
|
||||
rules: [{ required: true, message: t("authentication.oldPasswordRequired") }],
|
||||
},
|
||||
@@ -118,16 +123,18 @@ const passwordFormOptions: CrudOptions = {
|
||||
|
||||
async function open(opts: OpenOptions = {}) {
|
||||
const formOptions = buildFormOptions(passwordFormOptions);
|
||||
formOptions.newInstance = true; //新实例打开
|
||||
formOptions.newInstance = true;
|
||||
if (opts.init) {
|
||||
formOptions.wrapper.title = t("authentication.initPasswordTitle");
|
||||
}
|
||||
formOptions.wrapper.onClosed = () => {
|
||||
emit("close");
|
||||
};
|
||||
passwordFormRef.value = await openDialog(formOptions);
|
||||
passwordFormRef.value.setFormData({
|
||||
init: opts.init === true,
|
||||
password: opts.password || "",
|
||||
});
|
||||
console.log(passwordFormRef.value);
|
||||
}
|
||||
|
||||
const scope = ref({
|
||||
|
||||
@@ -107,6 +107,10 @@
|
||||
<div class="passkey-info">
|
||||
<div class="passkey-name">{{ passkey.deviceName }}</div>
|
||||
<div class="passkey-meta flex items-center">
|
||||
<span class="meta-item flex items-center">
|
||||
<fs-icon icon="ion:globe-outline" class="meta-icon" />
|
||||
{{ passkey.rpId || "-" }}
|
||||
</span>
|
||||
<span class="meta-item flex items-center">
|
||||
<fs-icon icon="ion:calendar-outline" class="meta-icon" />
|
||||
{{ formatDate(passkey.registeredAt) }}
|
||||
@@ -454,6 +458,8 @@ onMounted(async () => {
|
||||
}
|
||||
|
||||
.card-header {
|
||||
background: linear-gradient(145deg, #1e1e1e, #252525);
|
||||
|
||||
.header-bg-gradient {
|
||||
background: rgba(255, 255, 255, 0.04);
|
||||
opacity: 1;
|
||||
@@ -472,6 +478,7 @@ onMounted(async () => {
|
||||
|
||||
.detail-tag {
|
||||
background: #3b3b3b;
|
||||
border-color: rgba(255, 255, 255, 0.12);
|
||||
color: #e5e5e5;
|
||||
|
||||
.tag-icon {
|
||||
@@ -480,6 +487,23 @@ onMounted(async () => {
|
||||
}
|
||||
}
|
||||
|
||||
.card-title {
|
||||
border-bottom-color: rgba(255, 255, 255, 0.1);
|
||||
}
|
||||
|
||||
.binding-icon {
|
||||
background: linear-gradient(135deg, rgba(102, 126, 234, 0.22) 0%, rgba(160, 120, 234, 0.22) 100%);
|
||||
}
|
||||
|
||||
.passkey-icon {
|
||||
background: linear-gradient(135deg, rgba(17, 153, 142, 0.22) 0%, rgba(56, 239, 125, 0.22) 100%);
|
||||
}
|
||||
|
||||
.binding-icon .icon,
|
||||
.passkey-icon .icon {
|
||||
color: rgba(255, 255, 255, 0.7);
|
||||
}
|
||||
|
||||
.bindings-list {
|
||||
.binding-item {
|
||||
background: #2d2d2d;
|
||||
|
||||
@@ -2,22 +2,110 @@
|
||||
<fs-page class="home—index bg-neutral-100 dark:bg-black">
|
||||
<!-- <page-content />-->
|
||||
<dashboard-user />
|
||||
<change-password-button ref="changePasswordButtonRef" :show-button="false"></change-password-button>
|
||||
<change-password-button ref="changePasswordButtonRef" :show-button="false" @close="checkAndSetupAccount"></change-password-button>
|
||||
</fs-page>
|
||||
</template>
|
||||
|
||||
<script lang="ts" setup>
|
||||
<script lang="tsx" setup>
|
||||
import DashboardUser from "./dashboard/index.vue";
|
||||
import { useUserStore } from "/@/store/user";
|
||||
import ChangePasswordButton from "/@/views/certd/mine/change-password-button.vue";
|
||||
import { onMounted, ref } from "vue";
|
||||
import { Modal } from "ant-design-vue";
|
||||
import { Modal, notification } from "ant-design-vue";
|
||||
import { useI18n } from "/src/locales";
|
||||
import { request } from "/@/api/service";
|
||||
import { useFormDialog } from "/@/use/use-dialog";
|
||||
|
||||
const { t } = useI18n();
|
||||
const { openFormDialog } = useFormDialog();
|
||||
|
||||
const userStore = useUserStore();
|
||||
const changePasswordButtonRef = ref();
|
||||
const emailFormWrapperRef = ref<any>();
|
||||
|
||||
const validateEmailConfirm = async (_rule: any, value: string) => {
|
||||
if (!value) {
|
||||
return;
|
||||
}
|
||||
const formData = emailFormWrapperRef.value?.getFormData?.();
|
||||
if (formData && value !== formData.email) {
|
||||
throw new Error("两次输入的邮箱地址不一致");
|
||||
}
|
||||
};
|
||||
|
||||
async function checkAndSetupAccount() {
|
||||
try {
|
||||
const userInfo = userStore.getUserInfo as any;
|
||||
if (!userInfo.needInitAccount) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (userInfo.email) {
|
||||
await request({
|
||||
url: "/mine/accountInit",
|
||||
method: "post",
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
emailFormWrapperRef.value = await openFormDialog({
|
||||
title: "绑定邮箱",
|
||||
wrapper: {
|
||||
width: 560,
|
||||
},
|
||||
initialForm: { email: "", emailConfirm: "" },
|
||||
async onSubmit(form: any) {
|
||||
await request({
|
||||
url: "/mine/accountInit",
|
||||
method: "post",
|
||||
data: { email: form.email },
|
||||
});
|
||||
notification.success({
|
||||
message: "邮箱绑定成功",
|
||||
});
|
||||
},
|
||||
body: () => {
|
||||
return <a-alert class="mb-4" message="为保证用户体验,请先绑定邮箱,初始化您的账号" type="success" show-icon></a-alert>;
|
||||
},
|
||||
columns: {
|
||||
email: {
|
||||
title: "邮箱",
|
||||
type: "text",
|
||||
form: {
|
||||
col: { span: 24 },
|
||||
component: {
|
||||
placeholder: "请输入邮箱地址",
|
||||
},
|
||||
helper: "请输入您的邮箱",
|
||||
rules: [
|
||||
{ required: true, message: "请输入邮箱地址" },
|
||||
{ type: "email", message: "请输入有效的邮箱地址" },
|
||||
],
|
||||
},
|
||||
},
|
||||
emailConfirm: {
|
||||
title: "确认邮箱",
|
||||
type: "text",
|
||||
form: {
|
||||
col: { span: 24 },
|
||||
component: {
|
||||
placeholder: "请再次输入邮箱地址",
|
||||
},
|
||||
helper: "请再次输入邮箱,以确认邮箱地址无误",
|
||||
rules: [
|
||||
{ required: true, message: "请再次输入邮箱地址" },
|
||||
{ type: "email", message: "请输入有效的邮箱地址" },
|
||||
{ validator: validateEmailConfirm, trigger: "blur" },
|
||||
],
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
} catch (e) {
|
||||
console.error("AcmeAccount setup failed:", e);
|
||||
}
|
||||
}
|
||||
|
||||
onMounted(() => {
|
||||
if (userStore.getUserInfo.isWeak === true) {
|
||||
Modal.info({
|
||||
@@ -30,6 +118,9 @@ onMounted(() => {
|
||||
},
|
||||
okText: t("authentication.changeNow"),
|
||||
});
|
||||
} else {
|
||||
//两个弹框不要同时出现
|
||||
checkAndSetupAccount();
|
||||
}
|
||||
});
|
||||
</script>
|
||||
|
||||
@@ -450,7 +450,7 @@ export default function ({ crudExpose, context }: CreateCrudOptionsProps): Creat
|
||||
},
|
||||
},
|
||||
disabled: {
|
||||
title: t("certd.enableDisable"),
|
||||
title: t("certd.clickToToggle"),
|
||||
type: "dict-switch",
|
||||
dict: dict({
|
||||
data: [
|
||||
|
||||
@@ -3,6 +3,30 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
|
||||
|
||||
# [1.42.0](https://github.com/certd/certd/compare/v1.41.4...v1.42.0) (2026-07-05)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* 修复telegram - 符号转义问题 ([d5882f1](https://github.com/certd/certd/commit/d5882f16bedb09baf09ace92049b02872620f5dc))
|
||||
* **aliyun:** 修复阿里云CDN/DCDN根据证书自动匹配不到证书的bug ([1ae185d](https://github.com/certd/certd/commit/1ae185d0bc356f4678bc38ca0582ce3396f82ebe))
|
||||
|
||||
### Features
|
||||
|
||||
* 通过插件配置懒加载依赖,动态加载第三方依赖包,精简安装镜像大小 ([01568ca](https://github.com/certd/certd/commit/01568ca1489069046b5a89ebdd4ced2f7f6ddf93))
|
||||
|
||||
### Performance Improvements
|
||||
|
||||
* 阿里云ESA证书部署支持SaaS模式 ([82276b5](https://github.com/certd/certd/commit/82276b53a8474a18a3d0237050907c994fc748f0))
|
||||
* 【破坏性更新】 证书压缩包不再生成文件存储,而是实时打包下载,证书申请插件不再输出certZip ([7cff1a9](https://github.com/certd/certd/commit/7cff1a98424120585205889874b3ef4956a30583))
|
||||
* 火山引擎点播插件支持部署到自定义源站域名 ([095791c](https://github.com/certd/certd/commit/095791cdc2b7c1f4b913b634643afec5e30fe9b0))
|
||||
* 新增橙域网络(asia-isp) CDN证书部署插件 ([b48831e](https://github.com/certd/certd/commit/b48831e60b0059bef7ef9a34ab61c9dd2f684641))
|
||||
* 优化阿里云API网关增加翻页查询 ([ed58ae3](https://github.com/certd/certd/commit/ed58ae3c5339e4a0238a92acfe7ea6d2f566ea28))
|
||||
* 优化用户体验,首次访问时弹出邮箱账号绑定用以初始化账号 ([608cc2a](https://github.com/certd/certd/commit/608cc2a81ff0b4872c9fe11ed9c9c0b4b90a12a3))
|
||||
* 优化ACME账号字段的选择提示 ([bfd3cac](https://github.com/certd/certd/commit/bfd3cacc687fc5cbc3cb2ca3cadbc140de300dc2))
|
||||
* 支持全自动匹配部署宝塔网站证书 ([4dff48e](https://github.com/certd/certd/commit/4dff48e807c32a7623ec9206cf39c88e88f89f6a))
|
||||
* **cert-plugin:** 调整更新天数自动减半逻辑,仅7天ip证书生效,其他情况下不减半 ([56e5524](https://github.com/certd/certd/commit/56e5524a0f4af3645d70bc3b3ec750b45ba8de10))
|
||||
* **passkey:** passkey支持多域名rpid ([79f6586](https://github.com/certd/certd/commit/79f65868ca0f5162bbc2f935ce89abc28011d816))
|
||||
|
||||
## [1.41.4](https://github.com/certd/certd/compare/v1.41.3...v1.41.4) (2026-06-14)
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
|
||||
ALTER TABLE `sys_passkey` ADD COLUMN `rp_id` varchar(256) NULL;
|
||||
|
||||
DROP INDEX `index_passkey_passkey_id` ON `sys_passkey`;
|
||||
|
||||
ALTER TABLE `sys_passkey` ADD UNIQUE INDEX `index_passkey_passkey_id` (`passkey_id`);
|
||||
@@ -0,0 +1,6 @@
|
||||
|
||||
ALTER TABLE "sys_passkey" ADD COLUMN "rp_id" varchar(256) NULL;
|
||||
|
||||
DROP INDEX "index_passkey_passkey_id";
|
||||
|
||||
CREATE UNIQUE INDEX "index_passkey_passkey_id" ON "sys_passkey" ("passkey_id");
|
||||
@@ -0,0 +1,6 @@
|
||||
|
||||
ALTER TABLE "sys_passkey" ADD COLUMN "rp_id" varchar(256) NULL;
|
||||
|
||||
DROP INDEX "index_passkey_passkey_id";
|
||||
|
||||
CREATE UNIQUE INDEX "index_passkey_passkey_id" ON "sys_passkey" ("passkey_id");
|
||||
@@ -74,7 +74,7 @@ input:
|
||||
credentials链接,然后点击编辑按钮,查看Secret key和HMAC key
|
||||
|
||||
litessl:[litesslEAB页面](https://freessl.cn/automation/eab-manager),然后点击新增EAB
|
||||
required: false
|
||||
required: true
|
||||
encrypt: true
|
||||
mergeScript: |2-
|
||||
|
||||
@@ -92,7 +92,7 @@ input:
|
||||
title: EAB HMAC Key
|
||||
component:
|
||||
placeholder: 需要EAB的颁发机构生成账号时填写
|
||||
required: false
|
||||
required: true
|
||||
encrypt: true
|
||||
mergeScript: |2-
|
||||
|
||||
|
||||
@@ -6,7 +6,7 @@ name: AliyunDeployCertToESA
|
||||
title: 阿里云-部署至ESA
|
||||
icon: svg:icon-aliyun
|
||||
group: aliyun
|
||||
desc: 部署证书到阿里云ESA(边缘安全加速),自动删除过期证书
|
||||
desc: 部署证书到阿里云ESA(边缘安全加速),支持边缘证书和SaaS证书两种模式
|
||||
needPlus: false
|
||||
input:
|
||||
cert:
|
||||
@@ -70,6 +70,20 @@ input:
|
||||
type: aliyun
|
||||
required: true
|
||||
order: 0
|
||||
deployMode:
|
||||
title: 部署模式
|
||||
value: edge
|
||||
component:
|
||||
name: a-radio-group
|
||||
vModel: value
|
||||
options:
|
||||
- label: 边缘证书
|
||||
value: edge
|
||||
- label: SaaS证书
|
||||
value: saas
|
||||
helper: 边缘证书:将证书部署到站点的边缘节点;SaaS证书:将证书部署到站点的SaaS域名
|
||||
required: true
|
||||
order: 0
|
||||
siteIds:
|
||||
title: 站点
|
||||
component:
|
||||
@@ -99,6 +113,39 @@ input:
|
||||
|
||||
helper: 请选择要部署证书的站点
|
||||
order: 0
|
||||
saasDomainIds:
|
||||
title: SaaS域名
|
||||
component:
|
||||
name: remote-select
|
||||
vModel: value
|
||||
mode: tags
|
||||
type: plugin
|
||||
action: onGetCustomHostnameList
|
||||
search: false
|
||||
pager: false
|
||||
single: false
|
||||
watches:
|
||||
- certDomains
|
||||
- accessId
|
||||
- siteIds
|
||||
- accessId
|
||||
- regionId
|
||||
required: false
|
||||
mergeScript: |2-
|
||||
|
||||
return {
|
||||
show: ctx.compute(({form})=>{
|
||||
return form.deployMode === 'saas'
|
||||
}),
|
||||
component:{
|
||||
form: ctx.compute(({form})=>{
|
||||
return form
|
||||
})
|
||||
},
|
||||
}
|
||||
|
||||
helper: 请选择要部署证书的SaaS域名(SaaS证书模式下必选)
|
||||
order: 0
|
||||
certLimit:
|
||||
title: 免费证书数量限制
|
||||
value: 2
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
showRunStrategy: false
|
||||
default:
|
||||
strategy:
|
||||
runStrategy: 1
|
||||
name: BaotaAutoDeploySiteCert
|
||||
title: 宝塔-全自动部署
|
||||
icon: svg:icon-bt
|
||||
group: panel
|
||||
desc: 根据证书域名自动匹配宝塔站点,全自动部署SSL证书。新增加速域名自动感知,自动新增部署
|
||||
runStrategy: 0
|
||||
needPlus: true
|
||||
input:
|
||||
cert:
|
||||
title: 域名证书
|
||||
helper: 请选择前置任务输出的域名证书
|
||||
component:
|
||||
name: output-selector
|
||||
from:
|
||||
- ':cert:'
|
||||
required: true
|
||||
order: 0
|
||||
certDomains:
|
||||
title: 当前证书域名
|
||||
component:
|
||||
name: cert-domains-getter
|
||||
mergeScript: |2-
|
||||
|
||||
return {
|
||||
component:{
|
||||
inputKey: ctx.compute(({form})=>{
|
||||
return form.cert
|
||||
}),
|
||||
}
|
||||
}
|
||||
|
||||
template: false
|
||||
required: false
|
||||
order: 0
|
||||
accessId:
|
||||
title: 宝塔授权
|
||||
helper: 将自动查找证书匹配的站点,检查证书即将过期的站点并更新
|
||||
component:
|
||||
name: access-selector
|
||||
type: baota
|
||||
required: true
|
||||
order: 0
|
||||
output:
|
||||
deployedList:
|
||||
title: 已部署过的站点
|
||||
pluginType: deploy
|
||||
type: builtIn
|
||||
scriptFilePath: /plugins/plugin-plus/baota/plugins/plugin-deploy-automatch.js
|
||||
@@ -314,6 +314,7 @@ input:
|
||||
component:
|
||||
name: access-selector
|
||||
type: acmeAccount
|
||||
defaultSelect: true
|
||||
required: false
|
||||
helper: |-
|
||||
直接本地生成,无需外部注册
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@certd/ui-server",
|
||||
"version": "1.41.4",
|
||||
"version": "1.42.0",
|
||||
"description": "fast-server base midway",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
@@ -41,20 +41,20 @@
|
||||
"lint1": "eslint --fix"
|
||||
},
|
||||
"dependencies": {
|
||||
"@certd/acme-client": "^1.41.4",
|
||||
"@certd/basic": "^1.41.4",
|
||||
"@certd/commercial-core": "^1.41.4",
|
||||
"@certd/acme-client": "^1.42.0",
|
||||
"@certd/basic": "^1.42.0",
|
||||
"@certd/commercial-core": "^1.42.0",
|
||||
"@certd/cv4pve-api-javascript": "^8.4.2",
|
||||
"@certd/jdcloud": "^1.41.4",
|
||||
"@certd/lib-huawei": "^1.41.4",
|
||||
"@certd/lib-k8s": "^1.41.4",
|
||||
"@certd/lib-server": "^1.41.4",
|
||||
"@certd/midway-flyway-js": "^1.41.4",
|
||||
"@certd/pipeline": "^1.41.4",
|
||||
"@certd/plugin-cert": "^1.41.4",
|
||||
"@certd/plugin-lib": "^1.41.4",
|
||||
"@certd/plugin-plus": "^1.41.4",
|
||||
"@certd/plus-core": "^1.41.4",
|
||||
"@certd/jdcloud": "^1.42.0",
|
||||
"@certd/lib-huawei": "^1.42.0",
|
||||
"@certd/lib-k8s": "^1.42.0",
|
||||
"@certd/lib-server": "^1.42.0",
|
||||
"@certd/midway-flyway-js": "^1.42.0",
|
||||
"@certd/pipeline": "^1.42.0",
|
||||
"@certd/plugin-cert": "^1.42.0",
|
||||
"@certd/plugin-lib": "^1.42.0",
|
||||
"@certd/plugin-plus": "^1.42.0",
|
||||
"@certd/plus-core": "^1.42.0",
|
||||
"@koa/cors": "^5.0.0",
|
||||
"@midwayjs/bootstrap": "3.20.11",
|
||||
"@midwayjs/cache": "3.14.0",
|
||||
@@ -92,6 +92,7 @@
|
||||
"log4js": "^6.9.1",
|
||||
"lru-cache": "^11.0.1",
|
||||
"mitt": "^3.0.1",
|
||||
"mwtsc": "^1.15.1",
|
||||
"mysql2": "^3.14.0",
|
||||
"nanoid": "^5.0.7",
|
||||
"node-forge": "^1.3.1",
|
||||
@@ -115,11 +116,9 @@
|
||||
"uuid": "^10.0.0",
|
||||
"wechatpay-node-v3": "^2.2.1",
|
||||
"whoiser": "2.0.0-beta.10",
|
||||
"xml2js": "^0.6.2",
|
||||
"mwtsc": "^1.15.1"
|
||||
"xml2js": "^0.6.2"
|
||||
},
|
||||
"devDependencies": {
|
||||
"mwts": "^1.3.0",
|
||||
"@midwayjs/mock": "3.20.11",
|
||||
"@types/ali-oss": "^6.16.11",
|
||||
"@types/cache-manager": "^4.0.6",
|
||||
@@ -133,6 +132,7 @@
|
||||
"cross-env": "^7.0.3",
|
||||
"esmock": "^2.7.5",
|
||||
"mocha": "^10.6.0",
|
||||
"mwts": "^1.3.0",
|
||||
"prettier": "3.3.3",
|
||||
"rimraf": "^5.0.5",
|
||||
"ts-node": "^10.9.2",
|
||||
@@ -140,7 +140,7 @@
|
||||
"typescript": "^5.4.2",
|
||||
"why-is-node-running": "^3.2.2"
|
||||
},
|
||||
"lazyDependencies": {
|
||||
"lazyDependencies": {
|
||||
"@alicloud/fc20230330": "^4.1.7",
|
||||
"@alicloud/tea-typescript": "^1.8.0",
|
||||
"@alicloud/openapi-client": "^0.4.12",
|
||||
@@ -182,7 +182,6 @@
|
||||
"pnpm": {
|
||||
"neverBuiltDependencies": []
|
||||
},
|
||||
|
||||
"author": "anonymous",
|
||||
"license": "MIT"
|
||||
}
|
||||
|
||||
@@ -1,10 +1,14 @@
|
||||
import { BaseController, Constants, SysSettingsService } from "@certd/lib-server";
|
||||
import { AccessGetter, AccessService, BaseController, Constants, SysSettingsService } from "@certd/lib-server";
|
||||
import { ALL, Body, Controller, Inject, Post, Provide } from "@midwayjs/core";
|
||||
import { PasskeyService } from "../../../modules/login/service/passkey-service.js";
|
||||
import { RoleService } from "../../../modules/sys/authority/service/role-service.js";
|
||||
import { UserService } from "../../../modules/sys/authority/service/user-service.js";
|
||||
import { NotificationService } from "../../../modules/pipeline/service/notification-service.js";
|
||||
import { newAccess } from "@certd/pipeline";
|
||||
import { http, logger, utils } from "@certd/basic";
|
||||
import { ApiTags } from "@midwayjs/swagger";
|
||||
import { CodeService } from "../../../modules/basic/service/code-service.js";
|
||||
import { EmailService } from "../../../modules/basic/service/email-service.js";
|
||||
|
||||
/**
|
||||
*/
|
||||
@@ -27,6 +31,15 @@ export class MineController extends BaseController {
|
||||
@Inject()
|
||||
sysSettingsService: SysSettingsService;
|
||||
|
||||
@Inject()
|
||||
accessService: AccessService;
|
||||
|
||||
@Inject()
|
||||
notificationService: NotificationService;
|
||||
|
||||
@Inject()
|
||||
emailService: EmailService;
|
||||
|
||||
@Post("/info", { description: Constants.per.authOnly, summary: "查询用户信息" })
|
||||
public async info() {
|
||||
const userId = this.getUserId();
|
||||
@@ -41,6 +54,17 @@ export class MineController extends BaseController {
|
||||
delete user.password;
|
||||
//@ts-ignore
|
||||
user.needInitPassword = needInitPassword;
|
||||
|
||||
const { projectId } = await this.getProjectUserIdRead();
|
||||
const userProjectQuery = this.accessService.buildUserProjectQuery(userId, projectId);
|
||||
const existingAccess = await this.accessService.findOne({
|
||||
where: { type: "acmeAccount", subtype: "letsencrypt", ...userProjectQuery },
|
||||
});
|
||||
if (!existingAccess) {
|
||||
//@ts-ignore
|
||||
user.needInitAccount = true;
|
||||
}
|
||||
|
||||
return this.ok(user);
|
||||
}
|
||||
|
||||
@@ -122,4 +146,58 @@ export class MineController extends BaseController {
|
||||
});
|
||||
return this.ok({});
|
||||
}
|
||||
|
||||
@Post("/accountInit", { description: Constants.per.authOnly, summary: "初始化Let's Encrypt ACME账号和邮件通知" })
|
||||
public async accountInit(@Body("email") email?: string) {
|
||||
const { projectId, userId } = await this.getProjectUserIdWrite();
|
||||
|
||||
let userEmail = email;
|
||||
let user: any = null;
|
||||
if (!userEmail) {
|
||||
user = await this.userService.info(userId);
|
||||
userEmail = user.email;
|
||||
}
|
||||
if (!userEmail) {
|
||||
return this.ok({ needEmail: true });
|
||||
}
|
||||
|
||||
if (email) {
|
||||
if (!user) {
|
||||
user = await this.userService.info(userId);
|
||||
}
|
||||
if (!user.email) {
|
||||
await this.userService.updateEmail(userId, { email: userEmail });
|
||||
}
|
||||
}
|
||||
|
||||
await this.emailService.add(userId, userEmail);
|
||||
|
||||
await this.notificationService.getOrCreateDefault(userEmail, userId, projectId);
|
||||
|
||||
const getAccessById = this.accessService.getById.bind(this.accessService);
|
||||
const accessGetter = new AccessGetter(userId, projectId, getAccessById);
|
||||
const accessContext = {
|
||||
http,
|
||||
logger,
|
||||
utils,
|
||||
accessService: accessGetter,
|
||||
define: undefined,
|
||||
} as any;
|
||||
const access = await newAccess("acmeAccount", { caType: "letsencrypt", email: userEmail }, accessGetter, accessContext);
|
||||
const accountJson = await access.onGenerateAccount();
|
||||
|
||||
await this.accessService.add({
|
||||
type: "acmeAccount",
|
||||
name: "Let's Encrypt",
|
||||
userId,
|
||||
projectId,
|
||||
setting: JSON.stringify({
|
||||
caType: "letsencrypt",
|
||||
email: userEmail,
|
||||
account: accountJson,
|
||||
}),
|
||||
});
|
||||
|
||||
return this.ok({ success: true });
|
||||
}
|
||||
}
|
||||
|
||||
@@ -69,7 +69,7 @@ export class MinePasskeyController extends BaseController {
|
||||
public async getPasskeys() {
|
||||
const userId = this.getUserId();
|
||||
const passkeys = await this.passkeyService.find({
|
||||
select: ["id", "deviceName", "registeredAt", "transports", "passkeyId", "updateTime"],
|
||||
select: ["id", "deviceName", "registeredAt", "transports", "passkeyId", "rpId", "updateTime"],
|
||||
where: { userId },
|
||||
order: { registeredAt: "DESC" },
|
||||
});
|
||||
|
||||
@@ -11,7 +11,7 @@ export class PasskeyEntity {
|
||||
@Column({ name: "device_name", comment: "设备名称" })
|
||||
deviceName: string;
|
||||
|
||||
@Column({ name: "passkey_id", comment: "passkey_id" })
|
||||
@Column({ name: "passkey_id", comment: "passkey_id", unique: true })
|
||||
passkeyId: string;
|
||||
|
||||
@Column({ name: "public_key", comment: "公钥", type: "text" })
|
||||
@@ -23,6 +23,9 @@ export class PasskeyEntity {
|
||||
@Column({ name: "transports", comment: "传输方式", type: "text", nullable: true })
|
||||
transports: string;
|
||||
|
||||
@Column({ name: "rp_id", comment: "注册时的rpId,域名可能会变", nullable: true })
|
||||
rpId: string;
|
||||
|
||||
@Column({ name: "registered_at", comment: "注册时间" })
|
||||
registeredAt: number;
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import { cache, logger } from "@certd/basic";
|
||||
import { AuthException, BaseService, SysInstallInfo, SysSettingsService, SysSiteInfo } from "@certd/lib-server";
|
||||
import { AuthException, BaseService, SysSettingsService, SysSiteInfo } from "@certd/lib-server";
|
||||
import { isComm } from "@certd/plus-core";
|
||||
import { Inject, Provide, Scope, ScopeEnum } from "@midwayjs/core";
|
||||
import { InjectEntityModel } from "@midwayjs/typeorm";
|
||||
@@ -23,19 +23,15 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
return this.repository;
|
||||
}
|
||||
|
||||
async getRpInfo() {
|
||||
async getRpInfo(ctx: any) {
|
||||
let rpName = "Certd";
|
||||
if (isComm()) {
|
||||
const siteInfo = await this.sysSettingsService.getSetting<SysSiteInfo>(SysSiteInfo);
|
||||
rpName = siteInfo.title || rpName;
|
||||
}
|
||||
|
||||
const installInfo = await this.sysSettingsService.getSetting<SysInstallInfo>(SysInstallInfo);
|
||||
|
||||
const url = installInfo.bindUrl || "http://localhost:7001";
|
||||
const uri = new URL(url);
|
||||
const rpId = uri.hostname;
|
||||
const origin = uri.origin;
|
||||
const rpId = ctx.hostname;
|
||||
const origin = ctx.origin;
|
||||
|
||||
return {
|
||||
rpName,
|
||||
@@ -47,7 +43,7 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
const { generateRegistrationOptions } = await import("@simplewebauthn/server");
|
||||
const user = await this.userService.info(userId);
|
||||
|
||||
const { rpName, rpId } = await this.getRpInfo();
|
||||
const { rpName, rpId } = await this.getRpInfo(ctx);
|
||||
|
||||
const options = await generateRegistrationOptions({
|
||||
rpName: rpName,
|
||||
@@ -84,7 +80,7 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
throw new AuthException("注册验证失败");
|
||||
}
|
||||
|
||||
const { rpId, origin } = await this.getRpInfo();
|
||||
const { rpId, origin } = await this.getRpInfo(ctx);
|
||||
|
||||
let verification: any = null;
|
||||
const verifyReq = {
|
||||
@@ -115,7 +111,7 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
}
|
||||
|
||||
async generateAuthenticationOptions(ctx: any) {
|
||||
const { rpId } = await this.getRpInfo();
|
||||
const { rpId } = await this.getRpInfo(ctx);
|
||||
const { generateAuthenticationOptions } = await import("@simplewebauthn/server");
|
||||
const options = await generateAuthenticationOptions({
|
||||
rpID: rpId,
|
||||
@@ -146,13 +142,19 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
throw new AuthException("Passkey不存在");
|
||||
}
|
||||
|
||||
const { rpId, origin } = await this.getRpInfo();
|
||||
const { rpId, origin } = await this.getRpInfo(ctx);
|
||||
|
||||
if (passkey.rpId && passkey.rpId !== rpId) {
|
||||
throw new AuthException(`当前站点域名(${rpId})与Passkey注册域名(${passkey.rpId})不一致,请在${passkey.rpId}域名下使用该Passkey登录`);
|
||||
}
|
||||
|
||||
const expectedRPID = passkey.rpId || rpId;
|
||||
|
||||
const verification = await verifyAuthenticationResponse({
|
||||
response: credential,
|
||||
expectedChallenge: challenge,
|
||||
expectedOrigin: origin,
|
||||
expectedRPID: rpId,
|
||||
expectedRPID,
|
||||
requireUserVerification: false,
|
||||
credential: {
|
||||
id: passkey.passkeyId,
|
||||
@@ -166,6 +168,11 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
throw new AuthException("认证验证失败");
|
||||
}
|
||||
|
||||
if (!passkey.rpId) {
|
||||
passkey.rpId = rpId;
|
||||
await this.repository.save(passkey);
|
||||
}
|
||||
|
||||
cache.delete(`passkey:authentication:${challenge}`);
|
||||
|
||||
return {
|
||||
@@ -178,12 +185,15 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
async registerPasskey(userId: number, response: any, challenge: string, deviceName: string, ctx: any) {
|
||||
const verification = await this.verifyRegistrationResponse(userId, response, challenge, ctx);
|
||||
|
||||
const rpInfo = await this.getRpInfo(ctx);
|
||||
|
||||
await this.add({
|
||||
userId,
|
||||
passkeyId: verification.credentialId,
|
||||
publicKey: Buffer.from(verification.credentialPublicKey).toString("base64"),
|
||||
counter: verification.counter,
|
||||
deviceName,
|
||||
rpId: rpInfo.rpId,
|
||||
registeredAt: Date.now(),
|
||||
});
|
||||
|
||||
@@ -215,20 +225,4 @@ export class PasskeyService extends BaseService<PasskeyEntity> {
|
||||
const user = await this.userService.info(passkey.userId);
|
||||
return user;
|
||||
}
|
||||
|
||||
// private getRpId(ctx: any): string {
|
||||
// if (ctx && ctx.request && ctx.request.host) {
|
||||
// return ctx.request.host.split(':')[0];
|
||||
// }
|
||||
// return 'localhost';
|
||||
// }
|
||||
|
||||
// private getOrigin(ctx: any): string {
|
||||
// if (ctx && ctx.request) {
|
||||
// const protocol = ctx.request.protocol;
|
||||
// const host = ctx.request.host;
|
||||
// return `${protocol}://${host}`;
|
||||
// }
|
||||
// return 'https://localhost';
|
||||
// }
|
||||
}
|
||||
|
||||
@@ -310,27 +310,27 @@ export class RuntimeDepsService {
|
||||
});
|
||||
}
|
||||
|
||||
async importRuntime(specifier: string,logger?:ILogger) {
|
||||
async importRuntime(specifier: string, logger?: ILogger) {
|
||||
if (this.isNativeImportSpecifier(specifier)) {
|
||||
return await import(specifier);
|
||||
}
|
||||
|
||||
const resolved = await this.resolveImportSpecifier(specifier,logger);
|
||||
const resolved = await this.resolveImportSpecifier(specifier, logger);
|
||||
return await import(pathToFileURL(resolved).href);
|
||||
}
|
||||
|
||||
private async resolveImportSpecifier(specifier: string,logger?:ILogger) {
|
||||
private async resolveImportSpecifier(specifier: string, logger?: ILogger) {
|
||||
try {
|
||||
return this.resolveRuntimeSpecifier(specifier).resolved;
|
||||
} catch (runtimeError: any) {
|
||||
if (!this.isModuleNotFoundError(runtimeError)) {
|
||||
throw runtimeError;
|
||||
}
|
||||
return await this.resolveMissingRuntimeSpecifier(specifier, runtimeError,logger);
|
||||
return await this.resolveMissingRuntimeSpecifier(specifier, runtimeError, logger);
|
||||
}
|
||||
}
|
||||
|
||||
private async resolveMissingRuntimeSpecifier(specifier: string, runtimeError: any,logger?:ILogger) {
|
||||
private async resolveMissingRuntimeSpecifier(specifier: string, runtimeError: any, logger?: ILogger) {
|
||||
const packageName = this.parsePackageName(specifier);
|
||||
const lazyRange = this.lazyDependencies?.[packageName];
|
||||
if (!lazyRange) {
|
||||
@@ -341,7 +341,7 @@ export class RuntimeDepsService {
|
||||
}
|
||||
}
|
||||
try {
|
||||
await this.ensureLazyDependency(packageName,logger);
|
||||
await this.ensureLazyDependency(packageName, logger);
|
||||
return this.resolveRuntimeSpecifier(specifier).resolved;
|
||||
} catch (lazyError: any) {
|
||||
return this.resolveProjectSpecifier(specifier, lazyError).resolved;
|
||||
@@ -392,7 +392,7 @@ export class RuntimeDepsService {
|
||||
return parts[0];
|
||||
}
|
||||
|
||||
private async ensureLazyDependency(packageName: string,logger?:ILogger) {
|
||||
private async ensureLazyDependency(packageName: string, logger?: ILogger) {
|
||||
const range = this.lazyDependencies?.[packageName];
|
||||
if (!range) {
|
||||
throw new Error(`动态依赖未安装且未配置懒加载版本: ${packageName}`);
|
||||
@@ -400,7 +400,7 @@ export class RuntimeDepsService {
|
||||
const dependencies = {
|
||||
[packageName]: range,
|
||||
};
|
||||
await this.ensureDependencies({ dependencies,logger });
|
||||
await this.ensureDependencies({ dependencies, logger });
|
||||
}
|
||||
|
||||
private isModuleNotFoundError(error: any) {
|
||||
@@ -441,10 +441,11 @@ export class RuntimeDepsService {
|
||||
|
||||
private getDefineByPluginKey(pluginKey: string, owner?: RuntimeDependencyPluginDefine): RuntimeDependencyPluginDefine {
|
||||
const parts = pluginKey.split(":");
|
||||
let [pluginType, subtype, name] = parts;
|
||||
const [pluginType, subtype, rawName] = parts;
|
||||
let name = rawName;
|
||||
if (parts.length === 2) {
|
||||
name = subtype;
|
||||
}else if (parts.length === 3) {
|
||||
} else if (parts.length === 3) {
|
||||
//无修改
|
||||
} else {
|
||||
const ownerName = owner?.name || pluginKey;
|
||||
|
||||
@@ -131,7 +131,7 @@ export class RoleService extends BaseService<RoleEntity> {
|
||||
async delete(id: any) {
|
||||
const idArr = this.resolveIdArr(id);
|
||||
//@ts-ignore
|
||||
const urs:any = await this.userRoleService.find({ where: { roleId: In(idArr) } });
|
||||
const urs: any = await this.userRoleService.find({ where: { roleId: In(idArr) } });
|
||||
if (urs.length > 0) {
|
||||
throw new Error("该角色已被用户使用,无法删除");
|
||||
}
|
||||
|
||||
@@ -254,13 +254,16 @@ export class DeployCertToAliyunCDN extends AbstractTaskPlugin {
|
||||
const client = await this.getClient(access);
|
||||
|
||||
const pager = new Pager(data);
|
||||
const params = {
|
||||
DomainName: data.searchKey,
|
||||
const params: any = {
|
||||
PageSize: pager.pageSize || 100,
|
||||
PageNumber: pager.pageNo || 1,
|
||||
DomainSearchType: "fuzzy_match",
|
||||
};
|
||||
|
||||
if (data.searchKey) {
|
||||
params.DomainName = data.searchKey;
|
||||
}
|
||||
|
||||
const requestOption = {
|
||||
method: "POST",
|
||||
formatParams: false,
|
||||
|
||||
@@ -100,7 +100,7 @@ export class DeployCertToAliyunDCDN extends AbstractTaskPlugin {
|
||||
|
||||
if (this.domainMatchMode === "auto") {
|
||||
const { result, deployedList } = await this.autoMatchedDeploy({
|
||||
targetName: "CDN加速域名",
|
||||
targetName: "DCDN加速域名",
|
||||
uploadCert: async () => {
|
||||
return await sslClient.uploadCertOrGet(this.cert);
|
||||
},
|
||||
@@ -190,13 +190,15 @@ export class DeployCertToAliyunDCDN extends AbstractTaskPlugin {
|
||||
|
||||
const client = await this.getClient(access);
|
||||
const pager = new Pager(data);
|
||||
const params = {
|
||||
DomainName: data.searchKey,
|
||||
const params: any = {
|
||||
PageSize: pager.pageSize || 200,
|
||||
PageNumber: pager.pageNo || 1,
|
||||
DomainSearchType: "fuzzy_match",
|
||||
};
|
||||
|
||||
if (data.searchKey) {
|
||||
params.DomainName = data.searchKey;
|
||||
}
|
||||
const requestOption = {
|
||||
method: "POST",
|
||||
formatParams: false,
|
||||
|
||||
+114
@@ -0,0 +1,114 @@
|
||||
/// <reference types="mocha" />
|
||||
|
||||
import assert from "node:assert/strict";
|
||||
import { AliyunDeployCertToESA } from "./index.js";
|
||||
|
||||
describe("AliyunDeployCertToESA", () => {
|
||||
it("has deployMode field with default value 'edge'", () => {
|
||||
const input = (AliyunDeployCertToESA as any).define.input.deployMode;
|
||||
assert.equal(input.value, "edge");
|
||||
assert.equal(input.component.name, "a-radio-group");
|
||||
assert.deepEqual(input.component.options, [
|
||||
{ label: "边缘证书", value: "edge" },
|
||||
{ label: "SaaS证书", value: "saas" },
|
||||
]);
|
||||
});
|
||||
|
||||
it("has saasDomainIds field with conditional show", () => {
|
||||
const input = (AliyunDeployCertToESA as any).define.input.saasDomainIds;
|
||||
assert.equal(input.component.name, "remote-select");
|
||||
assert.equal(input.component.action, "onGetCustomHostnameList");
|
||||
assert.equal(input.required, false);
|
||||
assert.match(input.mergeScript, /form.deployMode === 'saas'/);
|
||||
});
|
||||
|
||||
it("executeSaaS throws error when no site is selected", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined } as any;
|
||||
plugin.deployMode = "saas";
|
||||
plugin.siteIds = [];
|
||||
|
||||
await assert.rejects(() => (plugin as any).executeSaaS(null, null, 1, "test"), /SaaS证书模式下请先选择站点/);
|
||||
});
|
||||
|
||||
it("executeSaaS throws error when multiple sites are selected", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined } as any;
|
||||
plugin.deployMode = "saas";
|
||||
plugin.siteIds = ["site1", "site2"];
|
||||
|
||||
await assert.rejects(() => (plugin as any).executeSaaS(null, null, 1, "test"), /SaaS证书模式下站点只能单选/);
|
||||
});
|
||||
|
||||
it("executeSaaS throws error when no SaaS domains selected", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined } as any;
|
||||
plugin.deployMode = "saas";
|
||||
plugin.siteIds = ["site1"];
|
||||
plugin.saasDomainIds = [];
|
||||
|
||||
await assert.rejects(() => (plugin as any).executeSaaS(null, null, 1, "test"), /SaaS证书模式下请选择要部署的SaaS域名/);
|
||||
});
|
||||
|
||||
it("executeSaaS calls UpdateCustomHostname for each selected SaaS domain", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined, error: () => undefined } as any;
|
||||
plugin.deployMode = "saas";
|
||||
plugin.siteIds = ["site1"];
|
||||
plugin.saasDomainIds = ["1001", "1002"];
|
||||
plugin.regionId = "cn-hangzhou";
|
||||
|
||||
const calledHostnameIds: number[] = [];
|
||||
const mockClient = {
|
||||
doRequest: async (req: any) => {
|
||||
calledHostnameIds.push(req.data.body.HostnameId);
|
||||
return {};
|
||||
},
|
||||
};
|
||||
|
||||
await (plugin as any).executeSaaS(mockClient, null, 12345, "test-cert");
|
||||
|
||||
assert.deepEqual(calledHostnameIds, [1001, 1002]);
|
||||
});
|
||||
|
||||
it("executeSaaS handles Certificate.Duplicated error gracefully", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined, error: () => undefined } as any;
|
||||
plugin.deployMode = "saas";
|
||||
plugin.siteIds = ["site1"];
|
||||
plugin.saasDomainIds = ["1001"];
|
||||
plugin.regionId = "cn-hangzhou";
|
||||
|
||||
let callCount = 0;
|
||||
const mockClient = {
|
||||
doRequest: async (req: any) => {
|
||||
callCount++;
|
||||
throw new Error("Certificate.Duplicated");
|
||||
},
|
||||
};
|
||||
|
||||
await (plugin as any).executeSaaS(mockClient, null, 12345, "test-cert");
|
||||
assert.equal(callCount, 1);
|
||||
});
|
||||
|
||||
it("executeEdge calls SetCertificate for each site", async () => {
|
||||
const plugin = new AliyunDeployCertToESA();
|
||||
plugin.logger = { info: () => undefined, error: () => undefined } as any;
|
||||
plugin.siteIds = ["site1", "site2"];
|
||||
plugin.certLimit = 2;
|
||||
|
||||
const calledSites: string[] = [];
|
||||
const mockClient = {
|
||||
doRequest: async (req: any) => {
|
||||
if (req.action === "SetCertificate") {
|
||||
calledSites.push(req.data.body.SiteId);
|
||||
}
|
||||
return { Result: [] };
|
||||
},
|
||||
};
|
||||
|
||||
await (plugin as any).executeEdge(mockClient, 12345, "test-cert");
|
||||
|
||||
assert.deepEqual(calledSites, ["site1", "site2"]);
|
||||
});
|
||||
});
|
||||
@@ -11,7 +11,7 @@ import dayjs from "dayjs";
|
||||
title: "阿里云-部署至ESA",
|
||||
icon: "svg:icon-aliyun",
|
||||
group: pluginGroups.aliyun.key,
|
||||
desc: "部署证书到阿里云ESA(边缘安全加速),自动删除过期证书",
|
||||
desc: "部署证书到阿里云ESA(边缘安全加速),支持边缘证书和SaaS证书两种模式",
|
||||
needPlus: false,
|
||||
default: {
|
||||
strategy: {
|
||||
@@ -76,6 +76,22 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
})
|
||||
accessId!: string;
|
||||
|
||||
@TaskInput({
|
||||
title: "部署模式",
|
||||
value: "edge",
|
||||
component: {
|
||||
name: "a-radio-group",
|
||||
vModel: "value",
|
||||
options: [
|
||||
{ label: "边缘证书", value: "edge" },
|
||||
{ label: "SaaS证书", value: "saas" },
|
||||
],
|
||||
},
|
||||
helper: "边缘证书:将证书部署到站点的边缘节点;SaaS证书:将证书部署到站点的SaaS域名",
|
||||
required: true,
|
||||
})
|
||||
deployMode!: "edge" | "saas";
|
||||
|
||||
@TaskInput(
|
||||
createRemoteSelectInputDefine({
|
||||
title: "站点",
|
||||
@@ -86,6 +102,29 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
)
|
||||
siteIds!: string[];
|
||||
|
||||
@TaskInput(
|
||||
createRemoteSelectInputDefine({
|
||||
title: "SaaS域名",
|
||||
helper: "请选择要部署证书的SaaS域名(SaaS证书模式下必选)",
|
||||
action: AliyunDeployCertToESA.prototype.onGetCustomHostnameList.name,
|
||||
watches: ["siteIds", "accessId", "regionId"],
|
||||
required: false,
|
||||
mergeScript: `
|
||||
return {
|
||||
show: ctx.compute(({form})=>{
|
||||
return form.deployMode === 'saas'
|
||||
}),
|
||||
component:{
|
||||
form: ctx.compute(({form})=>{
|
||||
return form
|
||||
})
|
||||
},
|
||||
}
|
||||
`,
|
||||
})
|
||||
)
|
||||
saasDomainIds!: string[];
|
||||
|
||||
@TaskInput({
|
||||
title: "免费证书数量限制",
|
||||
value: 2,
|
||||
@@ -135,20 +174,27 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
}
|
||||
|
||||
async execute(): Promise<void> {
|
||||
this.logger.info("开始部署证书到阿里云");
|
||||
this.logger.info("开始部署证书到阿里云ESA");
|
||||
const access = await this.getAccess<AliyunAccess>(this.accessId);
|
||||
|
||||
const client = await this.getClient(access);
|
||||
|
||||
const { certId, certName } = await this.getAliyunCertId(access);
|
||||
|
||||
if (this.deployMode === "saas") {
|
||||
await this.executeSaaS(client, certId, certName);
|
||||
} else {
|
||||
await this.executeEdge(client, certId, certName);
|
||||
}
|
||||
}
|
||||
|
||||
async executeEdge(client: AliyunClientV2, certId: number, certName: string) {
|
||||
this.logger.info("边缘证书模式");
|
||||
for (const siteId of this.siteIds) {
|
||||
await this.clearSiteLimitCert(client, siteId);
|
||||
try {
|
||||
const res = await client.doRequest({
|
||||
// 接口名称
|
||||
action: "SetCertificate",
|
||||
// 接口版本
|
||||
version: "2024-09-10",
|
||||
data: {
|
||||
body: {
|
||||
@@ -159,7 +205,7 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
},
|
||||
},
|
||||
});
|
||||
this.logger.info(`部署站点[${siteId}]证书成功:${JSON.stringify(res)}`);
|
||||
this.logger.info(`部署站点[${siteId}]边缘证书成功:${JSON.stringify(res)}`);
|
||||
} catch (e) {
|
||||
if (e.message.includes("Certificate.Duplicated")) {
|
||||
this.logger.info(`站点[${siteId}]证书已存在,无需重复部署`);
|
||||
@@ -176,6 +222,47 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
}
|
||||
}
|
||||
|
||||
async executeSaaS(client: AliyunClientV2, certId: number, certName: string) {
|
||||
this.logger.info("SaaS证书模式");
|
||||
|
||||
if (!this.siteIds || this.siteIds.length === 0) {
|
||||
throw new Error("SaaS证书模式下请先选择站点");
|
||||
}
|
||||
if (this.siteIds.length > 1) {
|
||||
throw new Error(`SaaS证书模式下站点只能单选,当前已选择 ${this.siteIds.length} 个站点,请修改为只选择一个站点`);
|
||||
}
|
||||
|
||||
if (!this.saasDomainIds || this.saasDomainIds.length === 0) {
|
||||
throw new Error("SaaS证书模式下请选择要部署的SaaS域名");
|
||||
}
|
||||
|
||||
for (const hostnameId of this.saasDomainIds) {
|
||||
this.logger.info(`开始更新SaaS域名[${hostnameId}]证书`);
|
||||
try {
|
||||
const res = await client.doRequest({
|
||||
action: "UpdateCustomHostname",
|
||||
version: "2024-09-10",
|
||||
data: {
|
||||
body: {
|
||||
HostnameId: parseInt(hostnameId, 10),
|
||||
SslFlag: "on",
|
||||
CertType: "cas",
|
||||
CasId: certId,
|
||||
CasRegion: this.regionId,
|
||||
},
|
||||
},
|
||||
});
|
||||
this.logger.info(`更新SaaS域名[${hostnameId}]证书成功:${JSON.stringify(res)}`);
|
||||
} catch (e) {
|
||||
if (e.message?.includes("Certificate.Duplicated")) {
|
||||
this.logger.info(`SaaS域名[${hostnameId}]证书已存在,无需重复部署`);
|
||||
} else {
|
||||
throw e;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
async getClient(access: AliyunAccess) {
|
||||
const endpoint = `esa.${this.regionId}.aliyuncs.com`;
|
||||
return access.getClient(endpoint);
|
||||
@@ -210,6 +297,48 @@ export class AliyunDeployCertToESA extends AbstractTaskPlugin {
|
||||
return this.ctx.utils.options.buildGroupOptions(options, this.certDomains);
|
||||
}
|
||||
|
||||
async onGetCustomHostnameList(data: any) {
|
||||
if (!this.accessId) {
|
||||
throw new Error("请选择Access授权");
|
||||
}
|
||||
if (!this.siteIds || this.siteIds.length === 0) {
|
||||
throw new Error("请先选择站点");
|
||||
}
|
||||
if (this.siteIds.length > 1) {
|
||||
throw new Error("SaaS模式下站点只能单选,请先修改站点选择");
|
||||
}
|
||||
|
||||
const siteId = this.siteIds[0];
|
||||
const access = await this.getAccess<AliyunAccess>(this.accessId);
|
||||
const client = await this.getClient(access);
|
||||
|
||||
const res = await client.doRequest({
|
||||
action: "ListCustomHostnames",
|
||||
version: "2024-09-10",
|
||||
data: {
|
||||
body: {
|
||||
SiteId: parseInt(siteId, 10),
|
||||
PageSize: 500,
|
||||
PageNumber: 1,
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
const hostnames = res?.Hostnames;
|
||||
if (!hostnames || hostnames.length === 0) {
|
||||
throw new Error("该站点下没有找到SaaS域名,请先在ESA控制台添加SaaS域名");
|
||||
}
|
||||
|
||||
const options = hostnames.map((item: any) => {
|
||||
return {
|
||||
label: `${item.Hostname}(${item.Status})`,
|
||||
value: String(item.HostnameId),
|
||||
domain: item.Hostname,
|
||||
};
|
||||
});
|
||||
return this.ctx.utils.options.buildGroupOptions(options, this.certDomains);
|
||||
}
|
||||
|
||||
async clearSiteExpiredCert(client: AliyunClientV2, siteId: string) {
|
||||
this.logger.info(`开始清理站点[${siteId}]过期证书`);
|
||||
const certListRes = await client.doRequest({
|
||||
|
||||
@@ -54,13 +54,7 @@ export class AsiaIspClient {
|
||||
/**
|
||||
* 生成 HMAC-SHA1 签名,结果做 URL-safe Base64(替换 + → -,/ → _)
|
||||
*/
|
||||
private buildSignature(opts: {
|
||||
body?: any;
|
||||
method: string;
|
||||
nonce: string;
|
||||
queryString: string;
|
||||
timestamp: string;
|
||||
}): string {
|
||||
private buildSignature(opts: { body?: any; method: string; nonce: string; queryString: string; timestamp: string }): string {
|
||||
const { body, method, nonce, queryString, timestamp } = opts;
|
||||
const sk = this.config.accessKeySecret;
|
||||
|
||||
@@ -71,13 +65,7 @@ export class AsiaIspClient {
|
||||
pieces.push(`body=${JSON.stringify(body)}`);
|
||||
}
|
||||
|
||||
pieces.push(
|
||||
`method=${method}`,
|
||||
`nonce=${nonce}`,
|
||||
`queryString=${queryString}`,
|
||||
`timestamp=${timestamp}`,
|
||||
`uri=${URI}`
|
||||
);
|
||||
pieces.push(`method=${method}`, `nonce=${nonce}`, `queryString=${queryString}`, `timestamp=${timestamp}`, `uri=${URI}`);
|
||||
|
||||
const message = pieces.join("&");
|
||||
const hmac = crypto.createHmac("sha1", sk).update(message).digest("base64");
|
||||
@@ -88,11 +76,7 @@ export class AsiaIspClient {
|
||||
/**
|
||||
* 通用 API 请求(完全对齐 Python 实现)
|
||||
*/
|
||||
async doRequest(req: {
|
||||
method: string;
|
||||
action: string;
|
||||
data?: any;
|
||||
}): Promise<any> {
|
||||
async doRequest(req: { method: string; action: string; data?: any }): Promise<any> {
|
||||
const { method, action, data } = req;
|
||||
const nonce = String(Math.floor(Math.random() * 90000000) + 10000000);
|
||||
const timestamp = Date.now().toString();
|
||||
@@ -205,9 +189,8 @@ export class AsiaIspClient {
|
||||
return certId;
|
||||
} catch (e: any) {
|
||||
const msg = e.message || "";
|
||||
const isExists = msg.includes("Certificate already exists") || e.code ==='80003' ||
|
||||
msg.includes("Certificate note name already exists") || e.code ==='80010'
|
||||
//返回数据: {"code":"80010","msg":"Certificate note name already exists","data":null}
|
||||
const isExists = msg.includes("Certificate already exists") || e.code === "80003" || msg.includes("Certificate note name already exists") || e.code === "80010";
|
||||
//返回数据: {"code":"80010","msg":"Certificate note name already exists","data":null}
|
||||
if (!isExists) {
|
||||
throw e;
|
||||
}
|
||||
@@ -240,11 +223,7 @@ export class AsiaIspClient {
|
||||
* 部署证书到 CDN 域名(修改域名配置,绑定证书)
|
||||
* PUT /openapi/v3/stat?action=domainModify
|
||||
*/
|
||||
async deployCertToDomain(req: {
|
||||
domain: string;
|
||||
certId: number;
|
||||
protocol: string;
|
||||
}): Promise<void> {
|
||||
async deployCertToDomain(req: { domain: string; certId: number; protocol: string }): Promise<void> {
|
||||
await this.doRequest({
|
||||
method: "PUT",
|
||||
action: "domainModify",
|
||||
@@ -256,4 +235,4 @@ export class AsiaIspClient {
|
||||
});
|
||||
this.logger.info(`部署证书到域名成功: ${req.domain}, certId=${req.certId}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -375,6 +375,7 @@ export class CertApplyPlugin extends CertApplyBasePlugin {
|
||||
component: {
|
||||
name: "access-selector",
|
||||
type: "acmeAccount",
|
||||
defaultSelect: true,
|
||||
},
|
||||
required: false,
|
||||
helper: "直接本地生成,无需外部注册\n点击选择按钮->添加->填写邮箱->生成账号即可",
|
||||
|
||||
@@ -150,7 +150,7 @@ export abstract class CertApplyBasePlugin extends CertApplyBaseConvertPlugin {
|
||||
// 检查有效期
|
||||
const leftDays = Math.floor((expires - dayjs().valueOf()) / (1000 * 60 * 60 * 24));
|
||||
this.logger.info(`证书有效期剩余天数:${leftDays}`);
|
||||
if (totalDays < maxDays) {
|
||||
if (totalDays < 10 && totalDays < maxDays) {
|
||||
this.logger.warn(`当前更新天数为${maxDays},证书总天数${totalDays},总天数小于更新天数(更新天数是指到期前多少天更新证书,您可以在任务配置中调整该值)`);
|
||||
maxDays = Math.floor(totalDays / 2);
|
||||
if (maxDays < 2) {
|
||||
|
||||
@@ -0,0 +1,115 @@
|
||||
/// <reference types="mocha" />
|
||||
/// <reference types="node" />
|
||||
|
||||
import assert from "node:assert/strict";
|
||||
|
||||
import { TelegramNotification } from "./index.js";
|
||||
|
||||
describe("TelegramNotification.replaceText", () => {
|
||||
let notification: TelegramNotification;
|
||||
|
||||
beforeEach(() => {
|
||||
notification = new TelegramNotification();
|
||||
});
|
||||
|
||||
it("转义横杠字符 -", () => {
|
||||
const result = notification.replaceText("defense-gameliti-one");
|
||||
assert.equal(result, "defense\\-gameliti\\-one");
|
||||
});
|
||||
|
||||
it("转义下划线 _", () => {
|
||||
const result = notification.replaceText("hello_world");
|
||||
assert.equal(result, "hello\\_world");
|
||||
});
|
||||
|
||||
it("转义星号 *", () => {
|
||||
const result = notification.replaceText("*bold text*");
|
||||
assert.equal(result, "\\*bold text\\*");
|
||||
});
|
||||
|
||||
it("转义方括号 []", () => {
|
||||
const result = notification.replaceText("[link]");
|
||||
assert.equal(result, "\\[link\\]");
|
||||
});
|
||||
|
||||
it("转义圆括号 ()", () => {
|
||||
const result = notification.replaceText("(url)");
|
||||
assert.equal(result, "\\(url\\)");
|
||||
});
|
||||
|
||||
it("转义波浪号 ~", () => {
|
||||
const result = notification.replaceText("~strike~");
|
||||
assert.equal(result, "\\~strike\\~");
|
||||
});
|
||||
|
||||
it("转义反引号 `", () => {
|
||||
const result = notification.replaceText("`code`");
|
||||
assert.equal(result, "\\`code\\`");
|
||||
});
|
||||
|
||||
it("转义大于号 >", () => {
|
||||
const result = notification.replaceText(">quote");
|
||||
assert.equal(result, "\\>quote");
|
||||
});
|
||||
|
||||
it("转义井号 #", () => {
|
||||
const result = notification.replaceText("#hashtag");
|
||||
assert.equal(result, "\\#hashtag");
|
||||
});
|
||||
|
||||
it("转义加号 +", () => {
|
||||
const result = notification.replaceText("+1");
|
||||
assert.equal(result, "\\+1");
|
||||
});
|
||||
|
||||
it("转义等号 =", () => {
|
||||
const result = notification.replaceText("a=b");
|
||||
assert.equal(result, "a\\=b");
|
||||
});
|
||||
|
||||
it("转义竖线 |", () => {
|
||||
const result = notification.replaceText("a|b");
|
||||
assert.equal(result, "a\\|b");
|
||||
});
|
||||
|
||||
it("转义花括号 {}", () => {
|
||||
const result = notification.replaceText("{key: value}");
|
||||
assert.equal(result, "\\{key: value\\}");
|
||||
});
|
||||
|
||||
it("转义点号 .", () => {
|
||||
const result = notification.replaceText("example.com");
|
||||
assert.equal(result, "example\\.com");
|
||||
});
|
||||
|
||||
it("转义感叹号 !", () => {
|
||||
const result = notification.replaceText("!important");
|
||||
assert.equal(result, "\\!important");
|
||||
});
|
||||
|
||||
it("转义反斜杠 \\", () => {
|
||||
const result = notification.replaceText("path\\to\\file");
|
||||
assert.equal(result, "path\\\\to\\\\file");
|
||||
});
|
||||
|
||||
it("普通文本不做修改", () => {
|
||||
const result = notification.replaceText("Hello World 123");
|
||||
assert.equal(result, "Hello World 123");
|
||||
});
|
||||
|
||||
it("空字符串返回空字符串", () => {
|
||||
const result = notification.replaceText("");
|
||||
assert.equal(result, "");
|
||||
});
|
||||
|
||||
it("混合多种特殊字符全部正确转义", () => {
|
||||
const input = "_*[]()~`>#+-=|{}.!\\";
|
||||
const result = notification.replaceText(input);
|
||||
assert.equal(result, "\\_\\*\\[\\]\\(\\)\\~\\`\\>\\#\\+\\-\\=\\|\\{\\}\\.\\!\\\\");
|
||||
});
|
||||
|
||||
it("域名中的点号和横杠都被转义", () => {
|
||||
const result = notification.replaceText("sub-domain.example.com");
|
||||
assert.equal(result, "sub\\-domain\\.example\\.com");
|
||||
});
|
||||
});
|
||||
@@ -60,7 +60,7 @@ export class TelegramNotification extends BaseNotification {
|
||||
|
||||
replaceText(text: string) {
|
||||
// .*()<> 等都需要用\\进行替换
|
||||
return text.replace(/[_*[\]()~`>#\+\-=|{}.!]/g, "\\$&");
|
||||
return text.replace(/[_*[\]()~`>#+\-=|{}.!\\]/g, "\\$&");
|
||||
// .replace(/([\\_*`|!.[\](){}>+#=~-])/gm, '\\$1')
|
||||
// return text.replace(/[\\.*()<>]/g, '\\$&');
|
||||
}
|
||||
|
||||
+1
-1
@@ -121,4 +121,4 @@ export class BaotaAutoDeploySiteCert extends AbstractPlusTaskPlugin {
|
||||
};
|
||||
}
|
||||
}
|
||||
new BaotaAutoDeploySiteCert();
|
||||
new BaotaAutoDeploySiteCert();
|
||||
|
||||
Reference in New Issue
Block a user