Repository navigation
Conversation
Also align wrangler.jsonc with the live Worker so CF Builds deploys to the existing service: - name: openlist-tsworkers -> openlist-worker - DB_DRIVER: auto -> kv (live binding is KV) - kv_namespaces: fill in the real namespace id Verified locally: - tsc: 0 errors in changed files (pre-existing duplicate-identifier errors in db_cipher.test.ts are unrelated and untouched) - edge build: dist-server/api/[...route].js compiled authUserFromReq with the new (user || user.disabled) -> null short-circuit; isTokenRevoked(jti) check intact - frontend dist rebuilt from frontend repo main: style-Xdg_lEeV.css now ships 72 .solid-contextmenu style blocks (the online deploy was missing this file, breaking the right-click menu), and /@init + /public/init_status are present (Worker init protocol healthy)
…count 401 - fetch-frontend.mjs default FRONTEND_GIT_URL now points at BAJJDY/OpenList-Frontend (fork) so CF Builds compiles the fixed guest login UI. FRONTEND_GIT_URL still overrides it. - meHandler returns "Account is disabled" instead of "Unauthorized" when the account exists but is disabled, so the frontend can tell apart “guest not enabled” from “invalid credentials”.
Sensitive fields (drive credentials, 2FA secrets, password hashes) were written to KV in plaintext. Enable aes-256-gcm (enc:v2: envelope) so new writes are sealed with the JWT_SECRET-derived key. Reads are prefix-based, so existing plaintext entries keep working and migrate to ciphertext on the next save. Syncs the repo with the Worker binding so wrangler deploy no longer resets it to none.
Frontend fix lives in BAJJDY/OpenList-Frontend@fa96247: - src/store/settings.ts: settings becomes a reactive signal + add refreshSettings() - src/pages/login/index.tsx: call refreshSettings() on mount so the guest login button reflects the current allow_guest setting after SPA logout The CF build runs scripts/fetch-frontend.mjs which clones this fork and builds the frontend from source (npm 4.2.6 lacks the Worker setup protocol, so the published dist is skipped automatically).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
禁用用户的已签发 JWT 仍然有效
authUserFromReq()只校验用户是否存在,未检查disabled字段,与middlewares.ts的getUserFromContext()行为不一致。管理员禁用某个账号(例如游客用户)后,该账号此前已签发的 JWT 仍然可用,最长持续到其
exp(默认 7 天)。/me对禁用账号返回笼统的Unauthorized前端拿到
401 Unauthorized无法区分「未登录」与「账号被禁用」,只能统一弹一个
Unauthorized提示。修复
authUserFromReq()增加disabled判断,与middlewares.ts对齐: