update:为安全考虑,绑定设备功能未处理之前,只限制一个账号注册

This commit is contained in:
hrz
2025-02-16 00:58:31 +08:00
parent 0bdc205497
commit 6566fc8ae3
5 changed files with 43 additions and 26 deletions
+21 -20
View File
@@ -1,26 +1,27 @@
<!doctype html>
<html lang="en" style="height: 100%;">
<head>
<meta charset="UTF-8" />
<link rel="icon" type="image/svg+xml" href="/vite.svg" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<head>
<meta charset="UTF-8"/>
<link rel="icon" href="/favicon.ico"/>
<meta name="viewport" content="width=device-width, initial-scale=1.0"/>
<title>智控台</title>
<style>
html, body {
margin: 0;
padding: 0;
height: 100%;
width: 100%;
overflow: hidden;
}
#app {
height: 100%;
width: 100%;
}
html, body {
margin: 0;
padding: 0;
height: 100%;
width: 100%;
overflow: hidden;
}
#app {
height: 100%;
width: 100%;
}
</style>
</head>
<body>
<div id="app"></div>
<script type="module" src="/src/main.js"></script>
</body>
</head>
<body>
<div id="app"></div>
<script type="module" src="/src/main.js"></script>
</body>
</html>
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

+2 -2
View File
@@ -105,7 +105,7 @@ def check_password(password):
:return: 如果密码满足条件,则返回True;否则返回False。
"""
# 检查密码长度
if len(password) < 10:
if len(password) < 8:
return False
# 检查是否包含英文字符和数字
@@ -116,7 +116,7 @@ def check_password(password):
if "xiaozhi" in password:
return False
if "123456" in password:
if "1234" in password:
return False
# 如果满足所有条件,则返回True
+20 -4
View File
@@ -1,9 +1,11 @@
import logging
from aiohttp import web
import datetime
from core.utils.util import check_password
logger = logging.getLogger(__name__)
class RegisterHandler:
def __init__(self, config):
self.config = config
@@ -15,18 +17,32 @@ class RegisterHandler:
username = data.get('username')
password = data.get('password')
if not check_password(password):
return web.json_response({
'success': False,
'message': '密码必须包含大小写字母、数字且长度至少8位'
})
if not username or not password:
logger.warning(f"Registration attempt with empty credentials from {request.remote}")
return web.json_response({
'success': False,
'success': False,
'message': '用户名和密码不能为空'
})
users = self.config.get('users', {})
# 由于现在所有用户都能看到所有设备,从安全角度上考虑,只允许注册一个用户
# 未来绑定设备功能完成后,再放开任意注册
if len(users) >= 1:
return web.json_response({
'success': False,
'message': '系统已经初始化过了,如果忘记了密码,请直接删除“.secrets.yaml”文件,删除后重启本服务'
})
if username in users:
logger.warning(f"Registration attempt with existing username {username} from {request.remote}")
return web.json_response({
'success': False,
'success': False,
'message': '用户名已存在'
})
@@ -39,13 +55,13 @@ class RegisterHandler:
logger.info(f"Successfully registered new user {username} from {request.remote}")
return web.json_response({
'success': True,
'success': True,
'message': '注册成功'
})
except Exception as e:
logger.error(f"Registration error: {str(e)}", exc_info=True)
return web.json_response({
'success': False,
'success': False,
'message': '注册失败,请稍后重试'
})