fix: simplify account password flow

This commit is contained in:
inman committed 2026-09-02 11:15:30 +08:00
1 parent 203bfb3246
commit df65e9f517
9 files changed
+118 -131

No files matched your search

@@ -67,14 +67,16 @@ test('account lifecycle is administrator-gated and protects passwords, sessions,
assert.match(auth, /last_admin_protected/);
assert.match(auth, /UPDATE sessions SET revoked_at = now\(\)/);
assert.match(auth, /must_change_password = false/);
assert.match(auth, /function validatePassword[\s\S]+if \(!password\)/);
assert.doesNotMatch(auth, /password\.length < 12|12—512/);
assert.match(auth, /account\.password_reset/);
assert.match(auth, /account\.password_changed/);
assert.match(server, /app\.get\('\/api\/accounts'[\s\S]+requireAdminSession\(request\)/);
assert.match(server, /app\.post\('\/api\/accounts'[\s\S]+requireAdminMutationSession\(request\)/);
assert.match(server, /app\.get\('\/api\/audit'[\s\S]+requireAdminSession\(request\)/);
assert.match(server, /password_change_required/);
assert.doesNotMatch(server, /password_change_required|must_change_password|\.min\(12\)/);
const publicUser = server.slice(server.indexOf('function publicUser'), server.indexOf('async function loadExternalParser'));
assert.match(publicUser, /must_change_password/);
assert.doesNotMatch(publicUser, /must_change_password/);
assert.doesNotMatch(publicUser, /organization/);
});
@@ -213,6 +215,7 @@ test('operator UI exposes role-aware accounts, executive drill-through, original
assert.match(index, /href="\/operations-dashboard"/);
assert.match(index, /id="passwordChangeForm"/);
assert.match(index, /id="accountForm"/);
assert.doesNotMatch(index, /accountMustChangePassword|首次登录必须修改密码|minlength="12"|12—512/);
assert.match(index, /id="accountAuthorizationPanel"/);
assert.match(index, /id="accountAuthorizationTypes"/);
assert.match(index, /id="accountAuthorizationSave"/);
@@ -231,6 +234,7 @@ test('operator UI exposes role-aware accounts, executive drill-through, original
assert.doesNotMatch(index, /OPERATIONS OVERVIEW|BUSINESS TRACE|指令操作历史/);
assert.match(index, /id="historyArchiveInput"/);
assert.match(app, /authUser\?\.role === 'admin'/);
assert.doesNotMatch(app, /passwordChangeForced|must_change_password/);
assert.match(app, /crypto\.randomUUID/);
assert.match(app, /\/api\/tasks\/\$\{encodeURIComponent\(taskId\)\}\/input-history/);
assert.match(app, /创建人与原始输入审计/);