Compare commits

...

8 Commits

Author SHA1 Message Date
xiaojunnuo 9acac86ed5 v1.37.11 2025-11-29 04:15:57 +08:00
xiaojunnuo ba5007219d build: prepare to build 2025-11-29 04:13:44 +08:00
xiaojunnuo ec046fd599 build: prepare to build 2025-11-29 04:10:55 +08:00
xiaojunnuo 5452ff1153 build: prepare to build 2025-11-29 04:08:56 +08:00
xiaojunnuo d03b1e0608 chore: 数据库脚本同步 2025-11-29 04:06:51 +08:00
xiaojunnuo 53c88ad5af perf: 优化天翼云cdn 等待5秒部署完成 2025-11-29 03:25:21 +08:00
xiaojunnuo 21585ca565 chore: 优化oidc登录 2025-11-28 01:42:42 +08:00
xiaojunnuo 2fabee647a fix: 修复阿里云 waf tlsVersion参数缺失导致部署失败的问题 2025-11-27 22:36:33 +08:00
57 changed files with 708 additions and 272 deletions
+17
View File
@@ -3,6 +3,23 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Bug Fixes
* 修复阿里云 waf tlsVersion参数缺失导致部署失败的问题 ([2fabee6](https://github.com/certd/certd/commit/2fabee647acf64afe689f5bea3603028cd0ba4a2))
* 修复备注撑开表格行高的bug ([c7b298c](https://github.com/certd/certd/commit/c7b298c46f0d52b43bd2bb17b374e7970a446446))
* 修复域名管理无法创建tencent-eo dns授权的bug ([3406bb5](https://github.com/certd/certd/commit/3406bb5a4a56bb310cddc1a1f410c70909fd129b))
* openapi 成功后失败都返回msg ([6e735bb](https://github.com/certd/certd/commit/6e735bbd1e29712e939f775a4db974db70e3b4b0))
### Performance Improvements
* ssh支持ppk格式私钥 ([575ae16](https://github.com/certd/certd/commit/575ae164c863d0b1f9fa0890549a2ee7472fb469))
* 优化宝塔网站证书在并发部署时导致nginx配置文件错乱的问题 ([51cc084](https://github.com/certd/certd/commit/51cc08411fd2dbab66d769b495dc1b0bf2f2578c))
* 优化天翼云cdn 等待5秒部署完成 ([53c88ad](https://github.com/certd/certd/commit/53c88ad5afe66a3f7c38b9b759747918913a4edc))
* 支持oidc单点登录 ([ec75afb](https://github.com/certd/certd/commit/ec75afbc44139dbe9da534d8a8c08a5b91f86d3c))
* ssl.com支持ecc ([b5ec047](https://github.com/certd/certd/commit/b5ec04723db48422f71041f4043002e7f5b450b1))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
### Performance Improvements ### Performance Improvements
+1 -1
View File
@@ -9,5 +9,5 @@
} }
}, },
"npmClient": "pnpm", "npmClient": "pnpm",
"version": "1.37.10" "version": "1.37.11"
} }
+6
View File
@@ -3,6 +3,12 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/publishlab/node-acme-client/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* ssl.com支持ecc ([b5ec047](https://github.com/publishlab/node-acme-client/commit/b5ec04723db48422f71041f4043002e7f5b450b1))
## [1.37.10](https://github.com/publishlab/node-acme-client/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/publishlab/node-acme-client/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/acme-client **Note:** Version bump only for package @certd/acme-client
+2 -2
View File
@@ -3,7 +3,7 @@
"description": "Simple and unopinionated ACME client", "description": "Simple and unopinionated ACME client",
"private": false, "private": false,
"author": "nmorsman", "author": "nmorsman",
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"module": "scr/index.js", "module": "scr/index.js",
"main": "src/index.js", "main": "src/index.js",
@@ -18,7 +18,7 @@
"types" "types"
], ],
"dependencies": { "dependencies": {
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@peculiar/x509": "^1.11.0", "@peculiar/x509": "^1.11.0",
"asn1js": "^3.0.5", "asn1js": "^3.0.5",
"axios": "^1.7.2", "axios": "^1.7.2",
+8
View File
@@ -3,6 +3,14 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* 优化宝塔网站证书在并发部署时导致nginx配置文件错乱的问题 ([51cc084](https://github.com/certd/certd/commit/51cc08411fd2dbab66d769b495dc1b0bf2f2578c))
* 优化天翼云cdn 等待5秒部署完成 ([53c88ad](https://github.com/certd/certd/commit/53c88ad5afe66a3f7c38b9b759747918913a4edc))
* ssl.com支持ecc ([b5ec047](https://github.com/certd/certd/commit/b5ec04723db48422f71041f4043002e7f5b450b1))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/basic **Note:** Version bump only for package @certd/basic
+1 -1
View File
@@ -1 +1 @@
23:49 04:13
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/basic", "name": "@certd/basic",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"module": "./dist/index.js", "module": "./dist/index.js",
+1 -1
View File
@@ -9,7 +9,7 @@ export class Locker {
} }
async execute(lockStr: string, callback: any, options?: { timeout?: number }) { async execute(lockStr: string, callback: any, options?: { timeout?: number }) {
const timeout = options?.timeout ?? 20000; const timeout = options?.timeout ?? 120000;
return this.asyncLocker.acquire(lockStr, callback, { timeout }); return this.asyncLocker.acquire(lockStr, callback, { timeout });
} }
} }
+4
View File
@@ -3,6 +3,10 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
**Note:** Version bump only for package @certd/pipeline
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/pipeline **Note:** Version bump only for package @certd/pipeline
+3 -3
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/pipeline", "name": "@certd/pipeline",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"module": "./dist/index.js", "module": "./dist/index.js",
@@ -18,8 +18,8 @@
"compile": "tsc --skipLibCheck --watch" "compile": "tsc --skipLibCheck --watch"
}, },
"dependencies": { "dependencies": {
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@certd/plus-core": "^1.37.10", "@certd/plus-core": "^1.37.11",
"dayjs": "^1.11.7", "dayjs": "^1.11.7",
"lodash-es": "^4.17.21", "lodash-es": "^4.17.21",
"reflect-metadata": "^0.1.13" "reflect-metadata": "^0.1.13"
+4
View File
@@ -3,6 +3,10 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
**Note:** Version bump only for package @certd/lib-huawei
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/lib-huawei **Note:** Version bump only for package @certd/lib-huawei
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/lib-huawei", "name": "@certd/lib-huawei",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"main": "./dist/bundle.js", "main": "./dist/bundle.js",
"module": "./dist/bundle.js", "module": "./dist/bundle.js",
"types": "./dist/d/index.d.ts", "types": "./dist/d/index.d.ts",
+4
View File
@@ -3,6 +3,10 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
**Note:** Version bump only for package @certd/lib-iframe
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/lib-iframe **Note:** Version bump only for package @certd/lib-iframe
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/lib-iframe", "name": "@certd/lib-iframe",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"module": "./dist/index.js", "module": "./dist/index.js",
+6
View File
@@ -3,6 +3,12 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* ssh支持ppk格式私钥 ([575ae16](https://github.com/certd/certd/commit/575ae164c863d0b1f9fa0890549a2ee7472fb469))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/jdcloud **Note:** Version bump only for package @certd/jdcloud
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@certd/jdcloud", "name": "@certd/jdcloud",
"version": "1.37.10", "version": "1.37.11",
"description": "jdcloud openApi sdk", "description": "jdcloud openApi sdk",
"main": "./dist/bundle.js", "main": "./dist/bundle.js",
"module": "./dist/bundle.js", "module": "./dist/bundle.js",
+4
View File
@@ -3,6 +3,10 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
**Note:** Version bump only for package @certd/lib-k8s
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/lib-k8s **Note:** Version bump only for package @certd/lib-k8s
+2 -2
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/lib-k8s", "name": "@certd/lib-k8s",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"module": "./dist/index.js", "module": "./dist/index.js",
@@ -17,7 +17,7 @@
"pub": "npm publish" "pub": "npm publish"
}, },
"dependencies": { "dependencies": {
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@kubernetes/client-node": "0.21.0" "@kubernetes/client-node": "0.21.0"
}, },
"devDependencies": { "devDependencies": {
+6
View File
@@ -3,6 +3,12 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* 支持oidc单点登录 ([ec75afb](https://github.com/certd/certd/commit/ec75afbc44139dbe9da534d8a8c08a5b91f86d3c))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/lib-server **Note:** Version bump only for package @certd/lib-server
+6 -6
View File
@@ -1,6 +1,6 @@
{ {
"name": "@certd/lib-server", "name": "@certd/lib-server",
"version": "1.37.10", "version": "1.37.11",
"description": "midway with flyway, sql upgrade way ", "description": "midway with flyway, sql upgrade way ",
"private": false, "private": false,
"type": "module", "type": "module",
@@ -28,11 +28,11 @@
], ],
"license": "AGPL", "license": "AGPL",
"dependencies": { "dependencies": {
"@certd/acme-client": "^1.37.10", "@certd/acme-client": "^1.37.11",
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@certd/pipeline": "^1.37.10", "@certd/pipeline": "^1.37.11",
"@certd/plugin-lib": "^1.37.10", "@certd/plugin-lib": "^1.37.11",
"@certd/plus-core": "^1.37.10", "@certd/plus-core": "^1.37.11",
"@midwayjs/cache": "3.14.0", "@midwayjs/cache": "3.14.0",
"@midwayjs/core": "3.20.11", "@midwayjs/core": "3.20.11",
"@midwayjs/i18n": "3.20.13", "@midwayjs/i18n": "3.20.13",
@@ -1,5 +1,5 @@
import { PermissionException, ValidateException } from './exception/index.js'; import { PermissionException, ValidateException } from './exception/index.js';
import { In, Repository, SelectQueryBuilder } from 'typeorm'; import { FindOneOptions, In, Repository, SelectQueryBuilder } from 'typeorm';
import { Inject } from '@midwayjs/core'; import { Inject } from '@midwayjs/core';
import { TypeORMDataSourceManager } from '@midwayjs/typeorm'; import { TypeORMDataSourceManager } from '@midwayjs/typeorm';
import { EntityManager } from 'typeorm/entity-manager/EntityManager.js'; import { EntityManager } from 'typeorm/entity-manager/EntityManager.js';
@@ -238,4 +238,8 @@ export abstract class BaseService<T> {
await this.delete(ids); await this.delete(ids);
} }
async findOne(options: FindOneOptions<T>) {
return await this.getRepository().findOne(options);
}
} }
@@ -31,6 +31,7 @@ export type AddonDefine = Registrable & {
[key: string]: AddonInputDefine; [key: string]: AddonInputDefine;
}; };
showTest?: boolean; showTest?: boolean;
icon?: string;
}; };
export type AddonInstanceConfig = { export type AddonInstanceConfig = {
@@ -3,6 +3,10 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
**Note:** Version bump only for package @certd/midway-flyway-js
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/midway-flyway-js **Note:** Version bump only for package @certd/midway-flyway-js
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@certd/midway-flyway-js", "name": "@certd/midway-flyway-js",
"version": "1.37.10", "version": "1.37.11",
"description": "midway with flyway, sql upgrade way ", "description": "midway with flyway, sql upgrade way ",
"private": false, "private": false,
"type": "module", "type": "module",
@@ -3,6 +3,12 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* ssl.com支持ecc ([b5ec047](https://github.com/certd/certd/commit/b5ec04723db48422f71041f4043002e7f5b450b1))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
### Performance Improvements ### Performance Improvements
+5 -5
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/plugin-cert", "name": "@certd/plugin-cert",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"types": "./dist/index.d.ts", "types": "./dist/index.d.ts",
@@ -17,10 +17,10 @@
"compile": "tsc --skipLibCheck --watch" "compile": "tsc --skipLibCheck --watch"
}, },
"dependencies": { "dependencies": {
"@certd/acme-client": "^1.37.10", "@certd/acme-client": "^1.37.11",
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@certd/pipeline": "^1.37.10", "@certd/pipeline": "^1.37.11",
"@certd/plugin-lib": "^1.37.10", "@certd/plugin-lib": "^1.37.11",
"@google-cloud/publicca": "^1.3.0", "@google-cloud/publicca": "^1.3.0",
"dayjs": "^1.11.7", "dayjs": "^1.11.7",
"jszip": "^3.10.1", "jszip": "^3.10.1",
+7
View File
@@ -3,6 +3,13 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Performance Improvements
* ssh支持ppk格式私钥 ([575ae16](https://github.com/certd/certd/commit/575ae164c863d0b1f9fa0890549a2ee7472fb469))
* 优化天翼云cdn 等待5秒部署完成 ([53c88ad](https://github.com/certd/certd/commit/53c88ad5afe66a3f7c38b9b759747918913a4edc))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
**Note:** Version bump only for package @certd/plugin-lib **Note:** Version bump only for package @certd/plugin-lib
+3 -3
View File
@@ -1,7 +1,7 @@
{ {
"name": "@certd/plugin-lib", "name": "@certd/plugin-lib",
"private": false, "private": false,
"version": "1.37.10", "version": "1.37.11",
"type": "module", "type": "module",
"main": "./dist/index.js", "main": "./dist/index.js",
"types": "./dist/index.d.ts", "types": "./dist/index.d.ts",
@@ -22,8 +22,8 @@
"@alicloud/pop-core": "^1.7.10", "@alicloud/pop-core": "^1.7.10",
"@alicloud/tea-util": "^1.4.10", "@alicloud/tea-util": "^1.4.10",
"@aws-sdk/client-s3": "^3.787.0", "@aws-sdk/client-s3": "^3.787.0",
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@certd/pipeline": "^1.37.10", "@certd/pipeline": "^1.37.11",
"@kubernetes/client-node": "0.21.0", "@kubernetes/client-node": "0.21.0",
"ali-oss": "^6.22.0", "ali-oss": "^6.22.0",
"basic-ftp": "^5.0.5", "basic-ftp": "^5.0.5",
@@ -36,7 +36,7 @@ export class TencentSslClient {
checkRet(ret: any) { checkRet(ret: any) {
if (!ret || ret.Error) { if (!ret || ret.Error) {
throw new Error("请求失败:" + ret.Error.Code + "," + ret.Error.Message); throw new Error("请求失败:" + ret.Error.Code + "," + ret.Error.Message + ",requestId" + ret.RequestId);
} }
} }
@@ -70,43 +70,33 @@ export class TencentSslClient {
} }
async deployCertificateInstance(params: any) { async deployCertificateInstance(params: any) {
const client = await this.getSslClient(); return await this.doRequest("DeployCertificateInstance", params);
const res = await client.DeployCertificateInstance(params);
this.checkRet(res);
return res;
} }
async DescribeHostUploadUpdateRecordDetail(params: any) { async DescribeHostUploadUpdateRecordDetail(params: any) {
const client = await this.getSslClient(); return await this.doRequest("DescribeHostUploadUpdateRecordDetail", params);
const res = await client.request("DescribeHostUploadUpdateRecordDetail", params);
this.checkRet(res);
return res;
} }
async UploadUpdateCertificateInstance(params: any) { async UploadUpdateCertificateInstance(params: any) {
const client = await this.getSslClient(); return await this.doRequest("UploadUpdateCertificateInstance", params);
const res = await client.request("UploadUpdateCertificateInstance", params);
this.checkRet(res);
return res;
} }
async DescribeCertificates(params: { Limit?: number; Offset?: number; SearchKey?: string }) { async DescribeCertificates(params: { Limit?: number; Offset?: number; SearchKey?: string }) {
const client = await this.getSslClient(); return await this.doRequest("DescribeCertificates", {
const res = await client.DescribeCertificates({
ExpirationSort: "ASC", ExpirationSort: "ASC",
...params, ...params,
}); });
this.checkRet(res);
return res;
} }
async doRequest(action: string, params: any) { async doRequest(action: string, params: any) {
const client = await this.getSslClient(); const client = await this.getSslClient();
if (!client[action]) { try {
throw new Error(`action ${action} not found`); const res = await client.request(action, params);
this.checkRet(res);
return res;
} catch (e) {
this.logger.error(`action ${action} error: ${e.message},requestId=${e.RequestId}`);
throw e;
} }
const res = await client[action](params);
this.checkRet(res);
return res;
} }
} }
+12
View File
@@ -3,6 +3,18 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Bug Fixes
* 修复备注撑开表格行高的bug ([c7b298c](https://github.com/certd/certd/commit/c7b298c46f0d52b43bd2bb17b374e7970a446446))
* 修复域名管理无法创建tencent-eo dns授权的bug ([3406bb5](https://github.com/certd/certd/commit/3406bb5a4a56bb310cddc1a1f410c70909fd129b))
### Performance Improvements
* 优化天翼云cdn 等待5秒部署完成 ([53c88ad](https://github.com/certd/certd/commit/53c88ad5afe66a3f7c38b9b759747918913a4edc))
* 支持oidc单点登录 ([ec75afb](https://github.com/certd/certd/commit/ec75afbc44139dbe9da534d8a8c08a5b91f86d3c))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
### Performance Improvements ### Performance Improvements
+3 -3
View File
@@ -1,6 +1,6 @@
{ {
"name": "@certd/ui-client", "name": "@certd/ui-client",
"version": "1.37.10", "version": "1.37.11",
"private": true, "private": true,
"scripts": { "scripts": {
"dev": "vite --open", "dev": "vite --open",
@@ -106,8 +106,8 @@
"zod-defaults": "^0.1.3" "zod-defaults": "^0.1.3"
}, },
"devDependencies": { "devDependencies": {
"@certd/lib-iframe": "^1.37.10", "@certd/lib-iframe": "^1.37.11",
"@certd/pipeline": "^1.37.10", "@certd/pipeline": "^1.37.11",
"@rollup/plugin-commonjs": "^25.0.7", "@rollup/plugin-commonjs": "^25.0.7",
"@rollup/plugin-node-resolve": "^15.2.3", "@rollup/plugin-node-resolve": "^15.2.3",
"@types/chai": "^4.3.12", "@types/chai": "^4.3.12",
@@ -1,8 +1,8 @@
<template> <template>
<div id="userLayout" :class="['user-layout-wrapper']"> <div id="userLayout" :class="['user-layout-wrapper']">
<div class="login-container flex-center"> <div class="login-container flex justify-start">
<div class="user-layout-content flex-center flex-col"> <div class="user-layout-content flex-col justify-start">
<div class="top flex flex-col items-center justify-center"> <div class="top flex flex-col items-center justify-start">
<div class="header flex flex-row items-center"> <div class="header flex flex-row items-center">
<img :src="siteInfo.loginLogo" class="logo" alt="logo" /> <img :src="siteInfo.loginLogo" class="logo" alt="logo" />
<span class="title"></span> <span class="title"></span>
@@ -10,8 +10,9 @@
<div class="desc">{{ siteInfo.slogan }}</div> <div class="desc">{{ siteInfo.slogan }}</div>
</div> </div>
<router-view /> <div class="flex-1 flex flex-col justify-start items-center">
<router-view />
</div>
<div class="footer"> <div class="footer">
<div class="copyright"> <div class="copyright">
<span v-if="!settingStore.isComm"> <span v-if="!settingStore.isComm">
@@ -57,6 +57,7 @@ export default {
passwordPlaceholder: "Please enter your password", passwordPlaceholder: "Please enter your password",
mobilePlaceholder: "Please enter your mobile number", mobilePlaceholder: "Please enter your mobile number",
loginButton: "Log In", loginButton: "Log In",
bindButton: "Bind Account",
forgotPassword: "Forgot password?", forgotPassword: "Forgot password?",
forgotAdminPassword: "Forgot admin password?", forgotAdminPassword: "Forgot admin password?",
registerLink: "Register", registerLink: "Register",
@@ -760,6 +760,13 @@ export default {
fixedCertExpireDays: "Fixed Cert Expire Days", fixedCertExpireDays: "Fixed Cert Expire Days",
fixedCertExpireDaysHelper: "Fixed cert expiration days, helpful for table list progress bar display", fixedCertExpireDaysHelper: "Fixed cert expiration days, helpful for table list progress bar display",
fixedCertExpireDaysRecommend: "Recommend 90", fixedCertExpireDaysRecommend: "Recommend 90",
enableOauth: "Enable OAuth2 Login",
oauthEnabledHelper: "Whether to enable OAuth2 login",
oauthProviders: "OAuth2 Login Providers",
oauthType: "OAuth2 Login Type",
oauthConfig: "OAuth2 Login Config",
oauthProviderSelectorPlaceholder: "Please select OAuth2 login provider",
}, },
}, },
modal: { modal: {
@@ -57,6 +57,7 @@ export default {
passwordPlaceholder: "请输入密码", passwordPlaceholder: "请输入密码",
mobilePlaceholder: "请输入手机号", mobilePlaceholder: "请输入手机号",
loginButton: "登录", loginButton: "登录",
bindButton: "绑定账号",
forgotPassword: "忘记密码?", forgotPassword: "忘记密码?",
forgotAdminPassword: "忘记管理员密码?", forgotAdminPassword: "忘记管理员密码?",
registerLink: "注册", registerLink: "注册",
@@ -604,7 +604,7 @@ export default {
limitUserPipelineCountHelper: "0为不限制", limitUserPipelineCountHelper: "0为不限制",
enableSelfRegistration: "开启自助注册", enableSelfRegistration: "开启自助注册",
enableUserValidityPeriod: "开启用户有效期", enableUserValidityPeriod: "开启用户有效期",
userValidityPeriodHelper: "有效期内用户可正常使用,失效后流水线将被停用", userValidityPeriodHelper: "有效期内用户可正常使用,失效后用户的流水线将被停用",
enableUsernameRegistration: "开启用户名注册", enableUsernameRegistration: "开启用户名注册",
enableEmailRegistration: "开启邮箱注册", enableEmailRegistration: "开启邮箱注册",
proFeature: "专业版功能", proFeature: "专业版功能",
@@ -761,6 +761,13 @@ export default {
fixedCertExpireDays: "固定证书有效期天数", fixedCertExpireDays: "固定证书有效期天数",
fixedCertExpireDaysHelper: "固定证书有效期天数,有助于列表进度条整齐显示", fixedCertExpireDaysHelper: "固定证书有效期天数,有助于列表进度条整齐显示",
fixedCertExpireDaysRecommend: "推荐90", fixedCertExpireDaysRecommend: "推荐90",
enableOauth: "启用第三方登录",
oauthEnabledHelper: "是否启用第三方登录",
oauthProviders: "第三方登录提供商",
oauthType: "第三方登录类型",
oauthConfig: "第三方登录配置",
oauthProviderSelectorPlaceholder: "请选择第三方登录提供商",
}, },
}, },
modal: { modal: {
@@ -22,3 +22,36 @@ export async function UpdateProfile(form: any) {
data: form, data: form,
}); });
} }
export async function GetOauthBounds() {
return await request({
url: "/oauth/bounds",
method: "POST",
});
}
export async function GetOauthProviders() {
return await request({
url: "/oauth/providers",
method: "POST",
});
}
export async function UnbindOauth(type: string) {
return await request({
url: "/oauth/unbind",
method: "POST",
data: { type },
});
}
export async function OauthBoundUrl(type: string) {
return await request({
url: "/oauth/login",
method: "POST",
data: {
type,
forType: "bind",
},
});
}
@@ -15,7 +15,14 @@
</a-descriptions-item> </a-descriptions-item>
<a-descriptions-item :label="t('authentication.email')">{{ userInfo.email }}</a-descriptions-item> <a-descriptions-item :label="t('authentication.email')">{{ userInfo.email }}</a-descriptions-item>
<a-descriptions-item :label="t('authentication.phoneNumber')">{{ userInfo.phoneCode }}{{ userInfo.mobile }}</a-descriptions-item> <a-descriptions-item :label="t('authentication.phoneNumber')">{{ userInfo.phoneCode }}{{ userInfo.mobile }}</a-descriptions-item>
<a-descriptions-item></a-descriptions-item> <a-descriptions-item v-if="settingStore.sysPublic.oauthEnabled && settingStore.isPlus" label="第三方账号绑定">
<div v-for="item in computedOauthBounds" :key="item.name" class="flex items-center gap-2">
<fs-icon :icon="item.icon" class="mr-2 text-blue-500" />
<span class="mr-2 w-36">{{ item.title }}</span>
<a-button v-if="item.bound" type="link" danger @click="unbind(item.name)">解绑</a-button>
<a-button v-else type="primary" @click="bind(item.name)">绑定</a-button>
</div>
</a-descriptions-item>
<a-descriptions-item :label="t('common.handle')"> <a-descriptions-item :label="t('common.handle')">
<a-button type="primary" @click="doUpdate">{{ t("authentication.updateProfile") }}</a-button> <a-button type="primary" @click="doUpdate">{{ t("authentication.updateProfile") }}</a-button>
<change-password-button class="ml-10" :show-button="true"> </change-password-button> <change-password-button class="ml-10" :show-button="true"> </change-password-button>
@@ -27,10 +34,12 @@
<script lang="ts" setup> <script lang="ts" setup>
import * as api from "./api"; import * as api from "./api";
import { Ref, ref } from "vue"; import { computed, onMounted, Ref, ref } from "vue";
import ChangePasswordButton from "/@/views/certd/mine/change-password-button.vue"; import ChangePasswordButton from "/@/views/certd/mine/change-password-button.vue";
import { useI18n } from "/src/locales"; import { useI18n } from "/src/locales";
import { useUserProfile } from "./use"; import { useUserProfile } from "./use";
import { Modal } from "ant-design-vue";
import { useSettingStore } from "/@/store/settings";
const { t } = useI18n(); const { t } = useI18n();
@@ -38,13 +47,13 @@ defineOptions({
name: "UserProfile", name: "UserProfile",
}); });
const settingStore = useSettingStore();
const userInfo: Ref = ref({}); const userInfo: Ref = ref({});
const getUserInfo = async () => { const getUserInfo = async () => {
userInfo.value = await api.getMineInfo(); userInfo.value = await api.getMineInfo();
}; };
getUserInfo();
const { openEditProfileDialog } = useUserProfile(); const { openEditProfileDialog } = useUserProfile();
function doUpdate() { function doUpdate() {
@@ -54,4 +63,51 @@ function doUpdate() {
}, },
}); });
} }
const oauthBounds = ref([]);
const oauthProviders = ref([]);
async function loadOauthBounds() {
const res = await api.GetOauthBounds();
oauthBounds.value = res;
}
async function loadOauthProviders() {
const res = await api.GetOauthProviders();
oauthProviders.value = res;
}
const computedOauthBounds = computed(() => {
const list = oauthProviders.value.map(item => {
const bound = oauthBounds.value.find(bound => bound.type === item.name);
return {
...item,
bound,
};
});
return list;
});
async function unbind(type: string) {
Modal.confirm({
title: "确认解绑吗?",
okText: "确认",
okType: "danger",
onOk: async () => {
await api.UnbindOauth(type);
await loadOauthBounds();
},
});
}
async function bind(type: string) {
//URL
const res = await api.OauthBoundUrl(type);
const loginUrl = res.loginUrl;
window.location.href = loginUrl;
}
onMounted(async () => {
await getUserInfo();
await loadOauthBounds();
await loadOauthProviders();
});
</script> </script>
@@ -48,28 +48,26 @@
</a-tabs> </a-tabs>
<a-form-item> <a-form-item>
<a-button type="primary" size="large" html-type="button" :loading="loading" class="login-button" @click="handleFinish"> <a-button type="primary" size="large" html-type="button" :loading="loading" class="login-button" @click="handleFinish">
{{ t("authentication.loginButton") }} {{ queryBindCode ? t("authentication.bindButton") : t("authentication.loginButton") }}
</a-button> </a-button>
<div v-if="!!settingStore.sysPublic.selfServicePasswordRetrievalEnabled && !queryBindCode" class="mt-2"> <div class="mt-2 flex justify-between items-center">
<router-link :to="{ name: 'forgotPassword' }"> <div class="flex items-center gap-2">
{{ t("authentication.forgotPassword") }} <language-toggle class="text-blue-500"></language-toggle>
</router-link> <router-link v-if="!!settingStore.sysPublic.selfServicePasswordRetrievalEnabled && !queryBindCode" :to="{ name: 'forgotPassword' }">
</div> {{ t("authentication.forgotPassword") }}
</a-form-item> </router-link>
</div>
<a-form-item class="user-login-other">
<div class="flex flex-between justify-between items-center">
<language-toggle class="color-blue"></language-toggle>
<router-link v-if="hasRegisterTypeEnabled() && !queryBindCode" class="register" :to="{ name: 'register' }"> <router-link v-if="hasRegisterTypeEnabled() && !queryBindCode" class="register" :to="{ name: 'register' }">
{{ t("authentication.registerLink") }} {{ t("authentication.registerLink") }}
</router-link> </router-link>
</div> </div>
<div class="flex flex-between justify-between items-center mt-5">
<oauth-footer></oauth-footer>
</div>
</a-form-item> </a-form-item>
<div v-if="!queryBindCode && settingStore.sysPublic.oauthEnabled && settingStore.isPlus" class="w-full">
<oauth-footer></oauth-footer>
</div>
</a-form> </a-form>
<a-form v-else ref="twoFactorFormRef" class="user-layout-login" :model="twoFactor" v-bind="layout"> <a-form v-else ref="twoFactorFormRef" class="user-layout-login" :model="twoFactor" v-bind="layout">
<div class="mb-10 flex flex-center">请打开您的Authenticator APP获取动态验证码</div> <div class="mb-10 flex flex-center">请打开您的Authenticator APP获取动态验证码</div>
@@ -84,7 +82,7 @@
<loading-button type="primary" size="large" html-type="button" class="login-button" :click="handleTwoFactorSubmit">OTP验证登录</loading-button> <loading-button type="primary" size="large" html-type="button" class="login-button" :click="handleTwoFactorSubmit">OTP验证登录</loading-button>
</a-form-item> </a-form-item>
<a-form-item class="user-login-other"> <a-form-item class="mt-10">
<a class="register" @click="twoFactor.loginId = null"> 返回 </a> <a class="register" @click="twoFactor.loginId = null"> 返回 </a>
</a-form-item> </a-form-item>
</a-form> </a-form>
@@ -2,23 +2,24 @@ import { request } from "/src/api/service";
const apiPrefix = "/oauth"; const apiPrefix = "/oauth";
export async function OauthLogin(type: string) { export async function OauthLogin(type: string, forType?: string) {
return await request({ return await request({
url: apiPrefix + `/login`, url: apiPrefix + `/login`,
method: "post", method: "post",
data: { data: {
type, type,
forType: forType || "login",
}, },
}); });
} }
export async function OauthCallback(type: string, query: Record<string, string>) { export async function OauthToken(type: string, validationCode: string) {
return await request({ return await request({
url: apiPrefix + `/callback`, url: apiPrefix + `/token`,
method: "post", method: "post",
data: { data: {
type, type,
...query, validationCode,
}, },
}); });
} }
@@ -43,3 +44,10 @@ export async function BindUser(code: string) {
}, },
}); });
} }
export async function GetOauthProviders() {
return await request({
url: apiPrefix + "/providers",
method: "post",
});
}
@@ -2,18 +2,19 @@
<div class="oauth-callback-page"> <div class="oauth-callback-page">
<div class="oauth-callback-content"> <div class="oauth-callback-content">
<div v-if="!bindRequired" class="oauth-callback-title"> <div v-if="!bindRequired" class="oauth-callback-title">
<span>登录中...</span> <span v-if="!error">登录中...</span>
<span v-else>{{ error }}</span>
</div> </div>
<div v-else class="oauth-callback-title"> <div v-else class="oauth-callback-title mt-10">
<div>第三方登录成功还未绑定账号请选择</div> <div>第三方{{ oauthType }}登录成功还未绑定账号请选择</div>
<div> <div class="mt-10">
<a-button class="w-full mt-5" type="primary" @click="goBindUser">绑定已有账号</a-button> <a-button class="w-full mt-10" type="primary" @click="goBindUser">绑定已有账号</a-button>
<a-button class="w-full mt-5" type="primary" @click="autoRegister">创建新账号</a-button> <a-button v-if="settingStore.sysPublic.registerEnabled" class="w-full mt-10" type="primary" @click="autoRegister">创建新账号</a-button>
</div> </div>
<div class="w-full mt-5"> <div class="w-full mt-10">
<router-link to="/login" class="w-full mt-5" type="primary">返回登录页</router-link> <router-link to="/login" class="w-full mt-10" type="primary">返回登录页</router-link>
</div> </div>
</div> </div>
</div> </div>
@@ -25,21 +26,24 @@ import { ref, onMounted } from "vue";
import * as api from "./api"; import * as api from "./api";
import { useRoute, useRouter } from "vue-router"; import { useRoute, useRouter } from "vue-router";
import { useUserStore } from "/@/store/user"; import { useUserStore } from "/@/store/user";
import { notification } from "ant-design-vue";
import { useSettingStore } from "/@/store/settings";
const route = useRoute(); const route = useRoute();
const router = useRouter(); const router = useRouter();
const settingStore = useSettingStore();
const oauthType = route.params.type as string; const oauthType = route.params.type as string;
const validationCode = route.query.validationCode as string;
const query = route.query as Record<string, string>; const forType = route.query.forType as string;
const error = ref(route.query.error as string);
const userStore = useUserStore(); const userStore = useUserStore();
const bindRequired = ref(false); const bindRequired = ref(false);
const bindCode = ref(""); const bindCode = ref("");
async function handleOauthCallback() { async function handleOauthToken() {
// //
const res = await api.OauthCallback(oauthType, query); const res = await api.OauthToken(oauthType, validationCode);
if (res.token) { if (res.token) {
// //
userStore.onLoginSuccess(res); userStore.onLoginSuccess(res);
@@ -55,7 +59,22 @@ async function handleOauthCallback() {
} }
onMounted(async () => { onMounted(async () => {
await handleOauthCallback(); if (error.value) {
return;
}
if (forType === "bind") {
//
await api.BindUser(validationCode);
notification.success({
message: "绑定成功",
});
//
router.replace("/certd/mine/user-profile");
return;
}
await handleOauthToken();
}); });
async function goBindUser() { async function goBindUser() {
@@ -83,7 +102,7 @@ async function autoRegister() {
justify-content: center; justify-content: center;
align-items: center; align-items: center;
gap: 16px; gap: 16px;
width: 100%;
.oauth-callback-content { .oauth-callback-content {
display: flex; display: flex;
justify-content: center; justify-content: center;
@@ -93,11 +112,14 @@ async function autoRegister() {
border-radius: 16px; border-radius: 16px;
box-shadow: 0 0 16px rgba(0, 0, 0, 0.1); box-shadow: 0 0 16px rgba(0, 0, 0, 0.1);
width: 500px; width: 500px;
max-width: 90%;
margin: 0 auto; margin: 0 auto;
margin-top: 50px; margin-top: 50px;
margin-bottom: 100px;
min-height: 200px;
.oauth-callback-title { .oauth-callback-title {
font-size: 24px; font-size: 16px;
font-weight: 500; font-weight: 500;
} }
} }
@@ -1,24 +1,25 @@
<template> <template>
<div class="oauth-footer"> <div class="oauth-footer relative">
<div class="oauth-title">
<div class="oauth-title-text">其他方式登录</div>
</div>
<div v-for="item in oauthList" :key="item.type"> <div v-for="item in oauthList" :key="item.type">
<div class="oauth-icon-button pointer" @click="goOauthLogin(item.type)"> <div class="oauth-icon-button pointer" @click="goOauthLogin(item.name)">
<el-icon :icon="item.icon" /> <div><fs-icon :icon="item.icon" class="text-blue-600 text-40" /></div>
<span>{{ item.name }}</span> <div>{{ item.title }}</div>
</div> </div>
</div> </div>
</div> </div>
</template> </template>
<script setup lang="ts"> <script setup lang="ts">
import { ref } from "vue"; import { onMounted, ref } from "vue";
import * as api from "./api"; import * as api from "./api";
const oauthList = ref([ const oauthList = ref([]);
{
name: "OIDC", onMounted(async () => {
type: "oidc", oauthList.value = await api.GetOauthProviders();
icon: "ion:oidc", });
},
]);
async function goOauthLogin(type: string) { async function goOauthLogin(type: string) {
//URL //URL
@@ -29,17 +30,56 @@ async function goOauthLogin(type: string) {
</script> </script>
<style lang="less"> <style lang="less">
.oauth-footer { .oauth-footer {
width: 100%;
display: flex; display: flex;
flex-direction: column;
justify-content: center; justify-content: center;
align-items: center; align-items: center;
gap: 16px; gap: 16px;
.oauth-title {
width: 100%;
font-size: 14px;
font-weight: 500;
color: #8c8c8c;
position: relative;
.oauth-title-text {
position: relative;
z-index: 1;
text-align: center;
&::after {
content: "";
position: absolute;
top: 50%;
left: 0;
width: 36%;
height: 0.5px;
background-color: #8c8c8c;
}
&::before {
content: "";
position: absolute;
top: 50%;
right: 0;
width: 36%;
height: 0.5px;
background-color: #8c8c8c;
}
}
}
.oauth-icon-button { .oauth-icon-button {
display: flex; display: flex;
flex-direction: column;
justify-content: center; justify-content: center;
align-items: center; align-items: center;
gap: 8px; gap: 8px;
padding: 8px 16px; padding: 8px 8px;
border-radius: 100px; border-radius: 100px;
.fs-icon {
font-size: 36px;
color: #006be6 !important;
}
} }
} }
</style> </style>
@@ -66,7 +66,7 @@ function onChange(value: string) {
<style lang="less"> <style lang="less">
.page-sys-settings { .page-sys-settings {
.sys-settings-form { .sys-settings-form {
width: 800px; width: 900px;
max-width: 100%; max-width: 100%;
padding: 20px; padding: 20px;
} }
@@ -54,34 +54,39 @@
<div class="helper">{{ t("certd.saveThenTest") }}</div> <div class="helper">{{ t("certd.saveThenTest") }}</div>
</a-form-item> </a-form-item>
</template> </template>
<a-form-item :label="t('certd.enableOauth')" :name="['public', 'oauthEnabled']"> </template>
<div class="flex-o">
<a-switch v-model:checked="formState.public.oauthEnabled" :disabled="!settingsStore.isPlus" :title="t('certd.plusFeature')" /> <a-form-item :label="t('certd.sys.setting.enableOauth')" :name="['public', 'oauthEnabled']">
<vip-button class="ml-5" mode="plus"></vip-button> <div class="flex-o">
</div> <a-switch v-model:checked="formState.public.oauthEnabled" :disabled="!settingsStore.isPlus" :title="t('certd.plusFeature')" />
</a-form-item> <vip-button class="ml-5" mode="button"></vip-button>
<a-form-item v-if="formState.public.oauthEnabled" :label="t('certd.oauthProviders')" :name="['public', 'oauthProviders']"> </div>
<div class="flex flex-wrap"> </a-form-item>
<table> <a-form-item v-if="formState.public.oauthEnabled" :label="t('certd.sys.setting.oauthProviders')" :name="['public', 'oauthProviders']">
<div class="flex flex-wrap">
<table class="w-full table-auto border-collapse border border-gray-400">
<thead>
<tr> <tr>
<th>{{ t("certd.oauthType") }}</th> <th class="border border-gray-300 px-4 py-2 w-1/2">{{ t("certd.sys.setting.oauthType") }}</th>
<th>{{ t("certd.oauthConfig") }}</th> <th class="border border-gray-300 px-4 py-2 w-1/2">{{ t("certd.sys.setting.oauthConfig") }}</th>
</tr> </tr>
</thead>
<tbody>
<tr v-for="(item, key) of oauthProviders" :key="key"> <tr v-for="(item, key) of oauthProviders" :key="key">
<td> <td class="border border-gray-300 px-4 py-2">
<div class="flex items-center"> <div class="flex items-center" :title="item.desc">
<fs-icon :icon="item.icon" /> <fs-icon :icon="item.icon" class="mr-2 text-blue-600" />
{{ item.title }} {{ item.title }}
</div> </div>
</td> </td>
<td> <td class="border border-gray-300 px-4 py-2">
<AddonSelector v-model:model-value="item.addonId" addon-type="oauth" from="sys" :type="item.name" :placeholder="t('certd.clientIdPlaceholder')" /> <AddonSelector v-model:model-value="item.addonId" addon-type="oauth" from="sys" :type="item.name" :placeholder="t('certd.sys.setting.oauthProviderSelectorPlaceholder')" />
</td> </td>
</tr> </tr>
</table> </tbody>
</div> </table>
</a-form-item> </div>
</template> </a-form-item>
<a-form-item label=" " :colon="false" :wrapper-col="{ span: 16 }"> <a-form-item label=" " :colon="false" :wrapper-col="{ span: 16 }">
<a-button :loading="saveLoading" type="primary" html-type="submit">{{ t("certd.saveButton") }}</a-button> <a-button :loading="saveLoading" type="primary" html-type="submit">{{ t("certd.saveButton") }}</a-button>
@@ -190,7 +195,6 @@ async function loadOauthProviders() {
let list: any = await api.GetOauthProviders(); let list: any = await api.GetOauthProviders();
oauthProviders.value = list; oauthProviders.value = list;
for (const item of list) { for (const item of list) {
debugger;
const type = item.name; const type = item.name;
const provider = formState.public.oauthProviders?.[type]; const provider = formState.public.oauthProviders?.[type];
if (provider) { if (provider) {
+12
View File
@@ -3,6 +3,18 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
See [Conventional Commits](https://conventionalcommits.org) for commit guidelines. See [Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.37.11](https://github.com/certd/certd/compare/v1.37.10...v1.37.11) (2025-11-28)
### Bug Fixes
* 修复阿里云 waf tlsVersion参数缺失导致部署失败的问题 ([2fabee6](https://github.com/certd/certd/commit/2fabee647acf64afe689f5bea3603028cd0ba4a2))
* 修复域名管理无法创建tencent-eo dns授权的bug ([3406bb5](https://github.com/certd/certd/commit/3406bb5a4a56bb310cddc1a1f410c70909fd129b))
### Performance Improvements
* 优化天翼云cdn 等待5秒部署完成 ([53c88ad](https://github.com/certd/certd/commit/53c88ad5afe66a3f7c38b9b759747918913a4edc))
* 支持oidc单点登录 ([ec75afb](https://github.com/certd/certd/commit/ec75afbc44139dbe9da534d8a8c08a5b91f86d3c))
## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19) ## [1.37.10](https://github.com/certd/certd/compare/v1.37.9...v1.37.10) (2025-11-19)
### Performance Improvements ### Performance Improvements
@@ -0,0 +1,14 @@
CREATE TABLE `cd_oauth_bound`
(
`id` bigint PRIMARY KEY AUTO_INCREMENT NOT NULL,
`user_id` bigint NOT NULL,
`type` varchar(512) NOT NULL,
`open_id` varchar(512) NOT NULL,
`create_time` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP,
`update_time` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP
);
CREATE INDEX `index_oauth_bound_user_id` ON `cd_oauth_bound` (`user_id`);
CREATE INDEX `index_oauth_bound_open_id` ON `cd_oauth_bound` (`open_id`);
@@ -0,0 +1,14 @@
CREATE TABLE "cd_oauth_bound"
(
"id" bigint PRIMARY KEY GENERATED BY DEFAULT AS IDENTITY NOT NULL,
"user_id" bigint NOT NULL,
"type" varchar(512) NOT NULL,
"open_id" varchar(512) NOT NULL,
"create_time" timestamp NOT NULL DEFAULT (CURRENT_TIMESTAMP),
"update_time" timestamp NOT NULL DEFAULT (CURRENT_TIMESTAMP)
);
CREATE INDEX "index_oauth_bound_user_id" ON "cd_oauth_bound" ("user_id");
CREATE INDEX "index_oauth_bound_open_id" ON "cd_oauth_bound" ("open_id");
+14 -14
View File
@@ -1,6 +1,6 @@
{ {
"name": "@certd/ui-server", "name": "@certd/ui-server",
"version": "1.37.10", "version": "1.37.11",
"description": "fast-server base midway", "description": "fast-server base midway",
"private": true, "private": true,
"type": "module", "type": "module",
@@ -45,20 +45,20 @@
"@aws-sdk/client-cloudfront": "^3.699.0", "@aws-sdk/client-cloudfront": "^3.699.0",
"@aws-sdk/client-iam": "^3.699.0", "@aws-sdk/client-iam": "^3.699.0",
"@aws-sdk/client-s3": "^3.705.0", "@aws-sdk/client-s3": "^3.705.0",
"@certd/acme-client": "^1.37.10", "@certd/acme-client": "^1.37.11",
"@certd/basic": "^1.37.10", "@certd/basic": "^1.37.11",
"@certd/commercial-core": "^1.37.10", "@certd/commercial-core": "^1.37.11",
"@certd/cv4pve-api-javascript": "^8.4.2", "@certd/cv4pve-api-javascript": "^8.4.2",
"@certd/jdcloud": "^1.37.10", "@certd/jdcloud": "^1.37.11",
"@certd/lib-huawei": "^1.37.10", "@certd/lib-huawei": "^1.37.11",
"@certd/lib-k8s": "^1.37.10", "@certd/lib-k8s": "^1.37.11",
"@certd/lib-server": "^1.37.10", "@certd/lib-server": "^1.37.11",
"@certd/midway-flyway-js": "^1.37.10", "@certd/midway-flyway-js": "^1.37.11",
"@certd/pipeline": "^1.37.10", "@certd/pipeline": "^1.37.11",
"@certd/plugin-cert": "^1.37.10", "@certd/plugin-cert": "^1.37.11",
"@certd/plugin-lib": "^1.37.10", "@certd/plugin-lib": "^1.37.11",
"@certd/plugin-plus": "^1.37.10", "@certd/plugin-plus": "^1.37.11",
"@certd/plus-core": "^1.37.10", "@certd/plus-core": "^1.37.11",
"@huaweicloud/huaweicloud-sdk-cdn": "^3.1.120", "@huaweicloud/huaweicloud-sdk-cdn": "^3.1.120",
"@huaweicloud/huaweicloud-sdk-core": "^3.1.120", "@huaweicloud/huaweicloud-sdk-core": "^3.1.120",
"@koa/cors": "^5.0.0", "@koa/cors": "^5.0.0",
@@ -1,14 +1,15 @@
import { addonRegistry, BaseController, Constants, SysInstallInfo, SysSettingsService } from "@certd/lib-server"; import { addonRegistry, BaseController, Constants, SysInstallInfo, SysSettingsService } from "@certd/lib-server";
import { ALL, Body, Controller, Inject, Post, Provide } from "@midwayjs/core"; import { ALL, Body, Controller, Get, Inject, Param, Post, Provide, Query } from "@midwayjs/core";
import { AddonGetterService } from "../../../modules/pipeline/service/addon-getter-service.js"; import { AddonGetterService } from "../../../modules/pipeline/service/addon-getter-service.js";
import { IOauthProvider } from "../../../plugins/plugin-oauth/api.js"; import { IOauthProvider } from "../../../plugins/plugin-oauth/api.js";
import { LoginService } from "../../../modules/login/service/login-service.js"; import { LoginService } from "../../../modules/login/service/login-service.js";
import { CodeService } from "../../../modules/basic/service/code-service.js"; import { CodeService } from "../../../modules/basic/service/code-service.js";
import { UserService } from "../../../modules/sys/authority/service/user-service.js"; import { UserService } from "../../../modules/sys/authority/service/user-service.js";
import { UserEntity } from "../../../modules/sys/authority/entity/user.js"; import { UserEntity } from "../../../modules/sys/authority/entity/user.js";
import { simpleNanoId } from "@certd/basic"; import { logger, simpleNanoId, utils } from "@certd/basic";
import { OauthBoundService } from "../../../modules/login/service/oauth-bound-service.js"; import { OauthBoundService } from "../../../modules/login/service/oauth-bound-service.js";
import { OauthBoundEntity } from "../../../modules/login/entity/oauth-bound.js"; import { OauthBoundEntity } from "../../../modules/login/entity/oauth-bound.js";
import { checkPlus } from "@certd/plus-core";
/** /**
*/ */
@@ -50,39 +51,95 @@ export class ConnectController extends BaseController {
} }
@Post('/login', { summary: Constants.per.guest }) @Post('/login', { summary: Constants.per.guest })
public async login(@Body(ALL) body: { type: string }) { public async login(@Body(ALL) body: { type: string, forType?:string }) {
const addon = await this.getOauthProvider(body.type); const addon = await this.getOauthProvider(body.type);
const installInfo = await this.sysSettingsService.getSetting<SysInstallInfo>(SysInstallInfo); const installInfo = await this.sysSettingsService.getSetting<SysInstallInfo>(SysInstallInfo);
const bindUrl = installInfo?.bindUrl || ""; const bindUrl = installInfo?.bindUrl || "";
//构造登录url //构造登录url
const redirectUrl = `${bindUrl}#/oauth/callback/${body.type}`; const redirectUrl = `${bindUrl}api/oauth/callback/${body.type}`;
const loginUrl = await addon.buildLoginUrl({ redirectUri: redirectUrl }); const { loginUrl, ticketValue } = await addon.buildLoginUrl({ redirectUri: redirectUrl, forType: body.forType });
return this.ok({loginUrl}); const ticket = this.codeService.setValidationValue(ticketValue)
this.ctx.cookies.set("oauth_ticket", ticket, {
httpOnly: true,
// secure: true,
// sameSite: "strict",
})
return this.ok({ loginUrl, ticket });
} }
@Post('/callback', { summary: Constants.per.guest }) @Get('/callback/:type', { summary: Constants.per.guest })
public async callback(@Body(ALL) body: any) { public async callback(@Param('type') type: string, @Query() query: Record<string, string>) {
checkPlus()
//处理登录回调 //处理登录回调
const addon = await this.getOauthProvider(body.type); const addon = await this.getOauthProvider(type);
const tokenRes = await addon.onCallback({ const request = this.ctx.request;
code: body.code, // const ticketValue = this.codeService.getValidationValue(ticket);
state: body.state, // if (!ticketValue) {
}); // throw new Error("登录ticket已过期");
// }
const userInfo = tokenRes.userInfo; const ticket = this.ctx.cookies.get("oauth_ticket");
if (!ticket) {
throw new Error("ticket已过期");
}
const ticketValue = this.codeService.getValidationValue(ticket);
if (!ticketValue) {
throw new Error("ticketValue已过期");
}
const openId = userInfo.openId; const installInfo = await this.sysSettingsService.getSetting<SysInstallInfo>(SysInstallInfo);
const bindUrl = installInfo?.bindUrl || "";
const currentUrl = `${bindUrl}api/oauth/callback/${type}?${request.querystring}`
try {
const tokenRes = await addon.onCallback({
code: query.code,
state: query.state,
ticketValue,
currentURL: new URL(currentUrl)
});
const userInfo = tokenRes.userInfo;
const loginRes = await this.loginService.loginByOpenId({ openId, type: body.type });
if (loginRes == null) {
// 用户还未绑定,让用户选择绑定已有账号还是自动注册新账号
const validationCode = await this.codeService.setValidationValue({ const validationCode = await this.codeService.setValidationValue({
type: body.type, type,
userInfo, userInfo,
}); });
const state = JSON.parse(utils.hash.base64Decode(query.state));
const redirectUrl = `${bindUrl}#/oauth/callback/${type}?validationCode=${validationCode}&forType=${state.forType}`;
this.ctx.redirect(redirectUrl);
} catch (err) {
logger.error(err);
this.ctx.redirect(`${bindUrl}#/oauth/callback/${type}?error=${err.error_description || err.message}`);
}
}
@Post('/token', { summary: Constants.per.guest })
public async token(@Body(ALL) body: { validationCode: string, type: string }) {
checkPlus()
const validationValue = await this.codeService.getValidationValue(body.validationCode);
if (!validationValue) {
throw new Error("校验码错误");
}
const type = validationValue.type;
if (type !== body.type) {
throw new Error("校验码错误");
}
const userInfo = validationValue.userInfo;
const openId = userInfo.openId;
const loginRes = await this.loginService.loginByOpenId({ openId, type });
if (loginRes == null) {
return this.ok({ return this.ok({
bindRequired: true, bindRequired: true,
validationCode, validationCode: body.validationCode,
}); });
} }
@@ -90,22 +147,6 @@ export class ConnectController extends BaseController {
return this.ok(loginRes); return this.ok(loginRes);
} }
@Post('/bind', { summary: Constants.per.loginOnly })
public async bind(@Body(ALL) body: any) {
//需要已登录
const userId = this.getUserId();
const validationValue = this.codeService.getValidationValue(body.validationCode);
if (!validationValue) {
throw new Error("校验码错误");
}
await this.oauthBoundService.bind({
userId,
type: body.type,
openId: validationValue.openId,
});
return this.ok(1);
}
@Post('/autoRegister', { summary: Constants.per.guest }) @Post('/autoRegister', { summary: Constants.per.guest })
public async autoRegister(@Body(ALL) body: { validationCode: string, type: string }) { public async autoRegister(@Body(ALL) body: { validationCode: string, type: string }) {
@@ -117,12 +158,12 @@ export class ConnectController extends BaseController {
const userInfo = validationValue.userInfo; const userInfo = validationValue.userInfo;
const oauthType = validationValue.type; const oauthType = validationValue.type;
let newUser = new UserEntity() let newUser = new UserEntity()
newUser.username = `${oauthType}:_${userInfo.nickName}_${simpleNanoId(6)}`; newUser.username = `${oauthType}_${userInfo.nickName}_${simpleNanoId(6)}`;
newUser.avatar = userInfo.avatar; newUser.avatar = userInfo.avatar;
newUser.nickName = userInfo.nickName; newUser.nickName = userInfo.nickName || simpleNanoId(6);
newUser = await this.userService.register("username", newUser, async (txManager) => { newUser = await this.userService.register("username", newUser, async (txManager) => {
const oauthBound : OauthBoundEntity = new OauthBoundEntity() const oauthBound: OauthBoundEntity = new OauthBoundEntity()
oauthBound.userId = newUser.id; oauthBound.userId = newUser.id;
oauthBound.type = oauthType; oauthBound.type = oauthType;
oauthBound.openId = userInfo.openId; oauthBound.openId = userInfo.openId;
@@ -133,6 +174,26 @@ export class ConnectController extends BaseController {
return this.ok(loginRes); return this.ok(loginRes);
} }
@Post('/bind', { summary: Constants.per.loginOnly })
public async bind(@Body(ALL) body: any) {
//需要已登录
const userId = this.getUserId();
const validationValue = this.codeService.getValidationValue(body.validationCode);
if (!validationValue) {
throw new Error("校验码错误");
}
const type = validationValue.type;
const userInfo = validationValue.userInfo;
const openId = userInfo.openId;
await this.oauthBoundService.bind({
userId,
type,
openId,
});
return this.ok(1);
}
@Post('/unbind', { summary: Constants.per.loginOnly }) @Post('/unbind', { summary: Constants.per.loginOnly })
public async unbind(@Body(ALL) body: any) { public async unbind(@Body(ALL) body: any) {
//需要已登录 //需要已登录
@@ -144,6 +205,18 @@ export class ConnectController extends BaseController {
return this.ok(1); return this.ok(1);
} }
@Post('/bounds', { summary: Constants.per.loginOnly })
public async bounds(@Body(ALL) body: any) {
//需要已登录
const userId = this.getUserId();
const bounds = await this.oauthBoundService.find({
where :{
userId,
}
});
return this.ok(bounds);
}
@Post('/providers', { summary: Constants.per.guest }) @Post('/providers', { summary: Constants.per.guest })
public async providers() { public async providers() {
const list = addonRegistry.getDefineList("oauth"); const list = addonRegistry.getDefineList("oauth");
@@ -44,8 +44,11 @@ export class OauthBoundService extends BaseService<OauthBoundEntity> {
type, type,
}, },
}); });
if (exist) { if (exist ) {
throw new Error('该第三方账号已绑定用户'); if(exist.userId === userId){
return;
}
throw new Error('该第三方账号已绑定其他用户');
} }
const exist2 = await this.repository.findOne({ const exist2 = await this.repository.findOne({
@@ -225,6 +225,7 @@ export class UserService extends BaseService<UserEntity> {
await this.transaction(async txManager => { await this.transaction(async txManager => {
newUser = await txManager.save(newUser); newUser = await txManager.save(newUser);
user.id = newUser.id;
const userRole: UserRoleEntity = UserRoleEntity.of(newUser.id, Constants.role.defaultUser); const userRole: UserRoleEntity = UserRoleEntity.of(newUser.id, Constants.role.defaultUser);
await txManager.save(userRole); await txManager.save(userRole);
@@ -99,27 +99,39 @@ export class AliyunDeployCertToALB extends AbstractTaskPlugin {
@TaskInput({ @TaskInput({
title: "部署证书类型", title: "部署证书类型",
value: "default", value: "default",
component: { component: {
name: "a-select", name: "a-select",
vModel: "value", vModel: "value",
options: [ options: [
{ {
label: "默认证书", label: "默认证书",
value: "default" value: "default"
}, },
{ {
label: "扩展证书", label: "扩展证书",
value: "extension" value: "extension"
} }
] ]
}, },
required: true required: true
} }
) )
deployType: string = "default"; deployType: string = "default";
@TaskInput({
title: "是否清理过期证书",
value: true,
component: {
name: "a-switch",
vModel: "checked",
},
required: true
}
)
clearExpiredCert: boolean;
async onInstance() { async onInstance() {
} }
@@ -155,17 +167,18 @@ export class AliyunDeployCertToALB extends AbstractTaskPlugin {
const client = await this.getLBClient(access, this.regionId); const client = await this.getLBClient(access, this.regionId);
await this.deployDefaultCert(certId, client); await this.deployDefaultCert(certId, client);
} }
this.logger.info(`准备开始清理过期证书`); if (this.clearExpiredCert!==false) {
await this.ctx.utils.sleep(30000) this.logger.info(`准备开始清理过期证书`);
for (const listener of this.listeners) { await this.ctx.utils.sleep(30000)
try{ for (const listener of this.listeners) {
await this.clearInvalidCert(albClientV2, listener); try {
}catch(e){ await this.clearInvalidCert(albClientV2, listener);
this.logger.error(`清理监听器${listener}的过期证书失败`, e); } catch (e) {
this.logger.error(`清理监听器${listener}的过期证书失败`, e);
}
} }
} }
this.logger.info("执行完成"); this.logger.info("执行完成");
} }
@@ -247,7 +260,7 @@ export class AliyunDeployCertToALB extends AbstractTaskPlugin {
if (item.IsDefault) { if (item.IsDefault) {
continue; continue;
} }
certIds.push( parseInt(item.CertificateId)); certIds.push(parseInt(item.CertificateId));
} }
this.logger.info(`监听器${listener}绑定的证书${certIds}`); this.logger.info(`监听器${listener}绑定的证书${certIds}`);
//检查是否过期,过期则删除 //检查是否过期,过期则删除
@@ -90,6 +90,35 @@ export class AliyunDeployCertToWaf extends AbstractTaskPlugin {
) )
cnameDomains!: string[]; cnameDomains!: string[];
@TaskInput({
title: 'TLS版本',
value: 'TLSv1.2',
component: {
name: 'a-select',
options: [
{ value: 'TLSv1', label: 'TLSv1' },
{ value: 'TLSv1.1', label: 'TLSv1.1' },
{ value: 'TLSv1.2', label: 'TLSv1.2' },
],
},
required: true,
})
tlsVersion!: string;
@TaskInput({
title: '启用TLSv3',
value: true,
component: {
name: 'a-switch',
vModel: 'checked',
},
required: true,
})
enableTLSv3!: boolean;
async onInstance() {} async onInstance() {}
async getWafClient(access: AliyunAccess) { async getWafClient(access: AliyunAccess) {
@@ -163,6 +192,8 @@ export class AliyunDeployCertToWaf extends AbstractTaskPlugin {
Redirect: JSON.stringify(redirect), Redirect: JSON.stringify(redirect),
Listen: JSON.stringify(listen), Listen: JSON.stringify(listen),
Domain: siteDomain, Domain: siteDomain,
TLSVersion: this.tlsVersion || 'TLSv1.2',
EnableTLSv3: this.enableTLSv3 ?? true,
}; };
const res = await client.request('ModifyDomain', updateParams); const res = await client.request('ModifyDomain', updateParams);
this.logger.info('部署成功', JSON.stringify(res)); this.logger.info('部署成功', JSON.stringify(res));
@@ -24,10 +24,10 @@ const regionDict = [
@IsTaskPlugin({ @IsTaskPlugin({
name: 'uploadCertToAliyun', name: 'uploadCertToAliyun',
title: '阿里云-上传证书到阿里云CAS', title: '阿里云-上传证书到CAS',
icon: 'svg:icon-aliyun', icon: 'svg:icon-aliyun',
group: pluginGroups.aliyun.key, group: pluginGroups.aliyun.key,
desc: '上传证书到阿里云数字证书管理服务(CAS),注意:不会部署到任何应用上;如果不想在阿里云上同一份证书上传多次,可以把此任务作为前置任务,其他阿里云任务证书那一项选择此任务的输出', desc: '上传证书到阿里云证书管理服务(CAS),如果不想在阿里云上同一份证书上传多次,可以把此任务作为前置任务,其他阿里云任务证书那一项选择此任务的输出',
default: { default: {
strategy: { strategy: {
runStrategy: RunStrategy.SkipWhenSucceed, runStrategy: RunStrategy.SkipWhenSucceed,
@@ -1,6 +1,8 @@
export type OnCallbackReq = { export type OnCallbackReq = {
code: string; code: string;
state: string; state: string;
currentURL: URL;
ticketValue: any;
} }
export type OauthToken = { export type OauthToken = {
@@ -30,8 +32,12 @@ export type OnBindReply = {
message: string; message: string;
} }
export type LoginUrlReply = {
loginUrl: string;
ticketValue: any;
}
export interface IOauthProvider { export interface IOauthProvider {
buildLoginUrl: (params: { redirectUri: string }) => Promise<string>; buildLoginUrl: (params: { redirectUri: string, forType?: string }) => Promise<LoginUrlReply>;
onCallback: (params: OnCallbackReq) => Promise<OauthToken>; onCallback: (params: OnCallbackReq) => Promise<OauthToken>;
onBind: (params: OnBindReq) => Promise<OnBindReply>;
} }
@@ -1,11 +1,12 @@
import { AddonInput, BaseAddon, IsAddon } from "@certd/lib-server"; import { AddonInput, BaseAddon, IsAddon } from "@certd/lib-server";
import { IOauthProvider, OnBindReq, OnCallbackReq } from "../api.js"; import { IOauthProvider, OnCallbackReq } from "../api.js";
@IsAddon({ @IsAddon({
addonType: "oauth", addonType: "oauth",
name: 'oidc', name: 'oidc',
title: 'OpenId connect 认证', title: 'OIDC认证',
desc: '', desc: 'OpenID Connect 认证,统一认证服务',
icon:"simple-icons:fusionauth",
showTest: false, showTest: false,
}) })
export class OidcOauthProvider extends BaseAddon implements IOauthProvider { export class OidcOauthProvider extends BaseAddon implements IOauthProvider {
@@ -28,7 +29,7 @@ export class OidcOauthProvider extends BaseAddon implements IOauthProvider {
@AddonInput({ @AddonInput({
title: "服务地址", title: "服务地址",
helper: "Issuer地址", helper: "Issuer地址,去掉/.well-known/openid-configuration的服务发现地址",
component: { component: {
placeholder: "https://oidc.example.com/oidc", placeholder: "https://oidc.example.com/oidc",
}, },
@@ -54,42 +55,8 @@ export class OidcOauthProvider extends BaseAddon implements IOauthProvider {
client client
} }
} }
async onCallback(req: OnCallbackReq) { async buildLoginUrl(params: { redirectUri: string, forType?: string }) {
const { config, client } = await this.getClient()
const currentUrl = new URL("")
let tokens: any = await client.authorizationCodeGrant(
config,
currentUrl,
{
pkceCodeVerifier: req.code,
expectedState: req.state,
},
)
console.log('Token Endpoint Response', tokens)
const claims = tokens.claims()
return {
token:{
accessToken: tokens.access_token,
refreshToken: tokens.refresh_token,
expiresIn: tokens.expires_in,
},
userInfo: {
openId: claims.sub,
nickName: claims.nickname,
avatar: claims.picture,
},
}
};
async onBind(req: OnBindReq) {
return {
success: false,
message: '绑定失败',
}
}
async buildLoginUrl(params: { redirectUri: string }) {
const { config, client } = await this.getClient() const { config, client } = await this.getClient()
let redirect_uri = new URL(params.redirectUri) let redirect_uri = new URL(params.redirectUri)
@@ -102,7 +69,10 @@ export class OidcOauthProvider extends BaseAddon implements IOauthProvider {
*/ */
let code_verifier = client.randomPKCECodeVerifier() let code_verifier = client.randomPKCECodeVerifier()
let code_challenge = await client.calculatePKCECodeChallenge(code_verifier) let code_challenge = await client.calculatePKCECodeChallenge(code_verifier)
let state = client.randomState() let state:any = {
forType: params.forType || 'login',
}
state = this.ctx.utils.hash.base64(JSON.stringify(state))
let parameters: any = { let parameters: any = {
redirect_uri, redirect_uri,
@@ -123,9 +93,40 @@ export class OidcOauthProvider extends BaseAddon implements IOauthProvider {
// } // }
let redirectTo = client.buildAuthorizationUrl(config, parameters) let redirectTo = client.buildAuthorizationUrl(config, parameters)
return {
// now redirect the user to redirectTo.href loginUrl: redirectTo.href,
console.log('redirecting to', redirectTo.href) ticketValue: {
return redirectTo.href; codeVerifier: code_verifier,
state,
},
};
} }
async onCallback(req: OnCallbackReq) {
const { config, client } = await this.getClient()
let tokens: any = await client.authorizationCodeGrant(
config,
req.currentURL,
{
expectedState: client.skipStateCheck ,
pkceCodeVerifier: req.ticketValue.codeVerifier,
}
)
const claims = tokens.claims()
return {
token:{
accessToken: tokens.access_token,
refreshToken: tokens.refresh_token,
expiresIn: tokens.expires_in,
},
userInfo: {
openId: claims.sub,
nickName: claims.nickname || claims.preferred_username || "",
avatar: claims.picture,
},
}
};
} }
@@ -124,6 +124,9 @@ export class TencentRefreshCert extends AbstractTaskPlugin {
let resourceTypes = [] let resourceTypes = []
const resourceTypesRegions = [] const resourceTypesRegions = []
if(!this.resourceTypesRegions){
this.resourceTypesRegions = []
}
for (const item of this.resourceTypesRegions) { for (const item of this.resourceTypesRegions) {
const [type,region] = item.split("_") const [type,region] = item.split("_")
if (!resourceTypes.includes( type)){ if (!resourceTypes.includes( type)){
@@ -156,13 +159,17 @@ export class TencentRefreshCert extends AbstractTaskPlugin {
break; break;
} }
retryCount++ retryCount++
deployRes = await sslClient.UploadUpdateCertificateInstance({ const params = {
OldCertificateId: certId, "OldCertificateId": certId,
"ResourceTypes": resourceTypes, "ResourceTypes": resourceTypes,
"CertificatePublicKey": this.cert.crt, "CertificatePublicKey": "xxx",
"CertificatePrivateKey": this.cert.key, "CertificatePrivateKey": "xxx",
"ResourceTypesRegions":resourceTypesRegions "ResourceTypesRegions":resourceTypesRegions
}); }
this.logger.info(`请求参数:${JSON.stringify(params)}`);
params.CertificatePublicKey = this.cert.crt
params.CertificatePrivateKey = this.cert.key
deployRes = await sslClient.UploadUpdateCertificateInstance(params);
if (deployRes && deployRes.DeployRecordId>0){ if (deployRes && deployRes.DeployRecordId>0){
this.logger.info(`任务创建成功,开始检查结果:${JSON.stringify(deployRes)}`); this.logger.info(`任务创建成功,开始检查结果:${JSON.stringify(deployRes)}`);
break; break;
@@ -325,7 +332,7 @@ export class TencentRefreshCert extends AbstractTaskPlugin {
*/ */
const options = list.map((item: any) => { const options = list.map((item: any) => {
return { return {
label: `${item.Alias}<${item.Domain}_${item.CertificateId}>`, label: `${item.CertificateId}<${item.Domain}_${item.Alias}_${item.BoundResource.length}>`,
value: item.CertificateId, value: item.CertificateId,
domain: item.SubjectAltName, domain: item.SubjectAltName,
}; };