feat: 新增 /admin 只读授权管理后台
- admin.py:HTTP Basic Auth + 服务端渲染单页,概览统计 / 用户与当前授权 / 最近使用记录 / 会话令牌 / 扫码场景五个区块 - ADMIN_PASSWORD 为空时返回 503 而非放行,避免漏配密码导致全库数据公开 - 不引模板引擎与 CDN,所有入库文本经 html.escape;令牌只显示首尾便于比对 - config.py / .env.example 新增 ADMIN_USER / ADMIN_PASSWORD - wechat.py 挂载 admin.router;CODEBUDDY.md 补充文档
This commit is contained in:
1 parent
3a8adda365
commit
f167550957
5 files changed
+410
-3
No files matched your search
@@ -4,7 +4,8 @@
|
||||
GET /wechat - 微信服务器验证(签名校验 + 返回 echostr)
|
||||
POST /wechat - 接收微信推送的消息和事件(subscribe / SCAN 触发扫码授权)
|
||||
|
||||
授权接口在 auth.py、使用扣减接口在 usage.py 中定义,通过 include_router 挂载。
|
||||
授权接口在 auth.py、使用扣减接口在 usage.py、管理后台在 admin.py 中定义,
|
||||
通过 include_router 挂载。
|
||||
"""
|
||||
|
||||
import hashlib
|
||||
@@ -16,6 +17,7 @@ from contextlib import asynccontextmanager
|
||||
from fastapi import FastAPI, HTTPException, Query, Request
|
||||
from fastapi.responses import PlainTextResponse
|
||||
|
||||
import admin
|
||||
import auth
|
||||
import db
|
||||
import usage
|
||||
@@ -41,6 +43,7 @@ async def lifespan(app: FastAPI):
|
||||
app = FastAPI(title="WeChat API", version="0.3.0", lifespan=lifespan)
|
||||
app.include_router(auth.router)
|
||||
app.include_router(usage.router)
|
||||
app.include_router(admin.router)
|
||||
|
||||
|
||||
def verify_signature(signature: str, timestamp: str, nonce: str) -> bool:
|
||||
|
||||
Reference in new issue
Block a user