chaos-zhu
|
4e84dd366a
|
docs: plan mobile native proxy support
|
2026-05-23 15:04:59 +08:00 |
|
chaos-zhu
|
eb6d572038
|
docs: design mobile native proxy support
|
2026-05-23 14:57:33 +08:00 |
|
chaos-zhu
|
88bd4cda3a
|
docs: plan mobile redesign and i18n implementation
|
2026-05-19 21:08:38 +08:00 |
|
chaos-zhu
|
fac3515aa5
|
docs: design mobile redesign and i18n
|
2026-05-19 20:56:47 +08:00 |
|
chaos-zhu
|
07c67d5e6d
|
docs(mobile): 第一轮迭代设计文档
|
2026-05-16 18:37:47 +08:00 |
|
chaos-zhu
|
5577fa91f6
|
feat(mobile): 添加 API 客户端与登录控制器
- core/api/api_result.dart: ApiFailure 包装非 2xx 响应,附带 statusCode
与 401/403 判定,便于跳登录。
- core/api/api_client.dart: dio 封装,固定 ${serverAddress}/api/v1 base,
token header + Set-Cookie 双向桥接,统一抛 ApiFailure。
- features/auth/auth_session.dart: 持有 token/deviceId/server/user。
- features/auth/login_controller.dart: 规范化地址 -> HTTP 风险确认 ->
获取公钥 -> RSA 加密密码 -> 调 /login -> 解析 token/deviceId;
通过 ApiClientFactory 注入便于测试,并提供 onLoginSuccess 钩子。
- 4 个 fake 模式单测覆盖 HTTP 风险、空用户名/密码、无效地址。
- 同步修订规范与计划: 不再生成自有 mobile deviceId,登录字段沿用
web 端 (loginName/ciphertext/jwtExpires/jwtExpireAt[/mfa2Token]),
使用服务端返回的 deviceId 以兼容 revoke-login API。
|
2026-05-16 17:07:02 +08:00 |
|
chaos-zhu
|
01d9e7e208
|
docs: 修订移动端原生终端方案,移除指纹绑定并明确加密回环
- 规范:login flow 去掉公钥指纹本地存储与变更对比;强提示限定在
HTTP 协议,RSA 公钥仍需用于加密登录密码与一次性 AES key。
- 规范:scope/测试列表加入移动端 deviceId(UUID v4,secure storage,
随登录上送),并在 SSH credential API 规则里点明 base64-then-RSA 回环
与错误信息脱敏要求。
- 实施计划:替换 fingerprint 子任务为 device_id;明确 jwtExpires 与
server/app/controller/user.js 中 beforeLoginHandler 兼容;rsa_crypto
在加密临时 key 前先 base64 编码 keyBytes;terminal 控制器新增
writeInput 将工具栏输入直发 SSH session;SSHKeyPair.fromPem 直接
使用其返回的 List;登录流程加入 deviceId 取出/生成与上送。
- server/app/controller/mobile.js:require terminal 提至顶端,端口
解析容错并保留 22 默认值,res.fail 仅返回通用错误,详细信息只写日志。
|
2026-05-16 16:49:41 +08:00 |
|
chaos-zhu
|
014353c71d
|
docs: add mobile native terminal implementation plan
|
2026-05-16 15:41:22 +08:00 |
|
chaos-zhu
|
52d2a682fa
|
docs: add mobile native terminal design
|
2026-05-16 15:36:32 +08:00 |
|