v1.0.51: 批次1架构筑基 - 1)版本迁移(common/migrate.php+schema_versions+natsort迁移文件);2)登录安全(bcrypt平滑迁移login/user_add/user_update旧sha1命中自动重写+system_login_attempts限流+session加固httponly/samesite/secure);3)CSRF Token(服务端checkCsrf+auth/csrf.php登录页取token+前端common.js/login.js统一携带X-CSRF-Token);4)统一基座common/Api.php并存量强制迁移全部70个endpoint(Api::boot按public/super/module/permissions分流,写接口强制checkAjax+checkCsrf,全局异常处理);5)前端收敛(common.js新增esc转义别名);6)REV-4硬数据来源渠道可编辑(hard_update+补全弹窗下拉);7)prepared卫生(soft_update.php修复+analysis.php表名白名单REV-9)
Co-Authored-By: Claude Code <noreply@anthropic.com>
This commit is contained in:
+5
-11
@@ -3,13 +3,9 @@
|
||||
* 新增用户接口 POST /api/system/user_add.php
|
||||
* 入参:username / password / real_name / role_id / is_active
|
||||
*/
|
||||
require_once __DIR__ . '/../common/db.php';
|
||||
require_once __DIR__ . '/../common/response.php';
|
||||
require_once __DIR__ . '/../common/auth.php';
|
||||
require_once __DIR__ . '/../common/logger.php';
|
||||
require_once __DIR__ . '/../common/Api.php';
|
||||
|
||||
checkAjax();
|
||||
checkPermission('system');
|
||||
$pdo = Api::boot(['module' => 'system']);
|
||||
|
||||
$username = trim($_POST['username'] ?? '');
|
||||
$password = (string)($_POST['password'] ?? '');
|
||||
@@ -20,15 +16,13 @@ $isActive = isset($_POST['is_active']) ? ((int)$_POST['is_active'] ? 1 : 0) : 1;
|
||||
if ($username === '' || !preg_match('/^[a-zA-Z0-9_]{3,50}$/', $username)) {
|
||||
Response::error('账号需为3-50位字母/数字/下划线', 400);
|
||||
}
|
||||
if (strlen($password) < 6) {
|
||||
Response::error('密码长度不能少于6位', 400);
|
||||
if (strlen($password) < 8 || !preg_match('/[a-zA-Z]/', $password) || !preg_match('/\d/', $password)) {
|
||||
Response::error('密码需不少于8位,且同时包含字母和数字', 400);
|
||||
}
|
||||
if ($roleId <= 0) {
|
||||
Response::error('请选择角色', 400);
|
||||
}
|
||||
|
||||
$pdo = DB::getInstance()->getPdo();
|
||||
|
||||
$chk = $pdo->prepare("SELECT COUNT(*) FROM system_users WHERE username = ?");
|
||||
$chk->execute([$username]);
|
||||
if ((int)$chk->fetchColumn() > 0) {
|
||||
@@ -45,7 +39,7 @@ $stmt = $pdo->prepare(
|
||||
"INSERT INTO system_users (username, password, real_name, role_id, is_active)
|
||||
VALUES (?, ?, ?, ?, ?)"
|
||||
);
|
||||
$stmt->execute([$username, sha1($password), $realName !== '' ? $realName : null, $roleId, $isActive]);
|
||||
$stmt->execute([$username, password_hash($password, PASSWORD_DEFAULT), $realName !== '' ? $realName : null, $roleId, $isActive]);
|
||||
$newId = (int)$pdo->lastInsertId();
|
||||
|
||||
logCurrent('add', 'system', 'system_users', $newId, ['username' => $username, 'role_id' => $roleId, 'is_active' => $isActive]);
|
||||
|
||||
Reference in New Issue
Block a user