Revert "feat(makelore): add platform oidc login"

This reverts commit 7236def07d.
This commit is contained in:
brother7 committed 2026-10-11 12:04:01 +08:00
1 parent f2a0eefc9e
commit e28beff3a6
11 files changed
+10 -475

No files matched your search

+2 -2
View File
@@ -21,7 +21,7 @@ Makelore 是一个面向软件、视觉创作、智能机器人与个人云智
- `Makelore Canvas|AI 绘画`:每个设计项目(Workspace)维护一份从创建起就存在的 Living Form。左侧项目栏负责新建、切换和管理 Workspace,并在桌面设计模式下以 256px 宽度常驻展开;中央沿用 AI 编程的安静对话画布、自然消息流和底部悬浮输入器,AI 整理出的制作方案作为对话内的轻量可编辑稿持续更新;桌面端右侧同为 256px 的全高历史作品栏集中展示当前项目的制作记录与生成结果。任务中的已生成图片可通过“放大查看图片”按钮直接打开大图,支持适应窗口、原始尺寸及 Esc 关闭,无需先下载。紧凑窗口通过左侧抽屉访问项目列表,历史记录保留在时间线中。参考图从本地上传后以 `@图片N` 绑定,具体用法只写在创作提示词中。
- `Makelore Robot|AI 机器`:管理机器人智能体、设备激活绑定、智能体配置与设备分配;机器人工作台的智能体位于 Robot 全局侧栏,选中后在内容区先查看绑定设备、再查看基础设置,当前智能体通过 URL 参数保持可分享选择;绑定设备时默认先选择“引导配网”或“已有激活码”。在 Windows 与 macOS 的引导路径中,Makelore 可在弹窗内扫描并连接附近开放的 `Xiaozhi-*` 配网热点,失败时仍可通过系统 Wi-Fi 手动连接;后续继续复用机器人现有热点配网页面,不修改固件,也不由 Makelore 接收 Wi-Fi 密码。
应用启动默认进入 AI 模块入口选择页。入口页可在未登录状态浏览;未登录用户点击已开通模块时进入客户端原生登录页,可使用平台账号 OIDC 登录,也可使用账号密码或手机号短信验证码登录。平台账号登录由 Electron Main 从 `PLATFORM_AUTH_ISSUER` 发现授权端点,使用系统浏览器完成 Authorization Code + PKCE(S256),回到 `niancode://auth/callback` 后由 Main 校验 state、交换令牌并保存会话;Renderer 不接触 client secret、refresh token 或授权回调凭据。密码登录可选“记住密码”:正式安装包仅由 Electron Main 使用系统受保护凭据存储加密保存和回填账号密码,不写入 Renderer 持久状态,未打包开发版或系统安全存储不可用时禁用该选项。登录请求由 Renderer 经 Host API 交给 Electron Main,再由 Main 调用 Works Square;成功后回到入口选择页。已登录时,Electron Main 会从 Works Square `/api/auth/me` 读取当前账号,只向 Renderer 投影用户名、账号/租户/部门标识、权限名列表与四个模块布尔开关,不透传上游资料或凭据。工作区门禁同时要求有效 Token 和完整用户身份;旧状态缺失身份时会先尝试从 Main 恢复,仍无法确认则清除残留会话并返回登录页。被管理员关闭的模块会在入口页置灰且无法点击,直接访问其工作区路径也会返回入口页。旧服务端未返回策略或缺少单项字段时默认开放;这个客户端门禁不替代服务端 API 授权。
应用启动默认进入 AI 模块入口选择页。入口页可在未登录状态浏览;未登录用户点击已开通模块时进入客户端原生登录页,可使用账号密码或手机号短信验证码登录。密码登录可选“记住密码”:正式安装包仅由 Electron Main 使用系统受保护凭据存储加密保存和回填账号密码,不写入 Renderer 持久状态,未打包开发版或系统安全存储不可用时禁用该选项。登录请求由 Renderer 经 Host API 交给 Electron Main,再由 Main 调用 Works Square;成功后回到入口选择页。已登录时,Electron Main 会从 Works Square `/api/auth/me` 读取当前账号,只向 Renderer 投影用户名、账号/租户/部门标识、权限名列表与四个模块布尔开关,不透传上游资料或凭据。工作区门禁同时要求有效 Token 和完整用户身份;旧状态缺失身份时会先尝试从 Main 恢复,仍无法确认则清除残留会话并返回登录页。被管理员关闭的模块会在入口页置灰且无法点击,直接访问其工作区路径也会返回入口页。旧服务端未返回策略或缺少单项字段时默认开放;这个客户端门禁不替代服务端 API 授权。
作品广场、素材广场、独立发布上传和云部署页面不属于 Makelore 2.0 工作台。新建 Code 项目只要求选择目录:Main 自动生成内部项目 ID,并以内部 `interactive_ai_app` 类型创建 `.makelore/project.json` 与 `knowledge/`,不再让用户选择或查看项目身份、项目类型和模板;缺少项目 ID 的旧项目在读取时由 Main 自动补全。从列表移除项目只取消登记,不删除磁盘文件;在“新建项目”中直接选择已有项目文件夹会重新打开,并保留原有项目身份、类型、智能体、对话和知识文件。“新建下级文件夹”仍拒绝已存在的同名目录。创建成功后直接进入对话工作区,未创建智能体时只显示可选的设置入口,不再用初始化门禁遮挡工作区。已有 `custom` 项目继续受支持;历史 `mini_game` / `mini_program` 配置在读取时归一为交互式 AI 应用,但不会因读取被改写。用户获取并为项目启用官方 bundled `makelore.project-scaffold` 插件后,每个父智能体都可按需明确调用 `makelore-project-scaffold` Skill,无需伙伴分配;它以不覆盖既有路径的方式生成固定六文件 Vite 起步工程,不是创建前置条件,也不安装依赖、不联网、不构建、不上传或提审。交互式 AI 应用的项目配置底部提供“一键提交审核”;Main 自动预检、安全打包并提交,构建通过后进入运营审核,审核通过即直接发布。首次创建必须选择 PNG、JPEG 或 WebP 项目封面,并通过 Main-owned multipart 原子接口同时保存资料与封面;已有 draft/published 只提交新版本并沿用平台现有资料与封面。项目成果预览 `/deliverables` 继续保留。
@@ -111,7 +111,7 @@ Pi 正式包必须继续运行 `pnpm run verify:artifact:pi`、`pnpm run smoke:p
- Renderer 的后端调用统一经过 `src/lib/host-api.ts` 或 `src/lib/api-client.ts`;请求先经 Main-owned IPC,再由兼容 Host API 路由处理。只有真正需要 URL 的资源和流会把 loopback 地址暴露给 Renderer。
- Renderer 不直接调用 Electron IPC 或本地运行时 HTTP 地址。
- Electron Main 负责认证、秘密存储、运行时生命周期、代理、同步和系统集成;所有 stream、watcher、poller、loopback server 与子进程必须登记到模块活动和任务租约,不允许页面自行创建无托管后台任务。
- 平台账号 OIDC 登录与 Works Square 原生密码、短信登录均沿 Renderer → Host API → Electron Main → Works Square 链路完成。OIDC 使用公开 `makelore` client、精确回调 `niancode://auth/callback`、state/nonce 和 S256 PKCE;Main 在会话切换前清理旧账号的本地运行时,再持久化新的平台 access/refresh token。登录态按真实键盘、鼠标或触摸活动滑动续期;持续使用无需反复登录,连续 7 天未使用才清除会话并要求重新登录。刷新凭据始终只由 Electron Main 持有,并在正式安装包中通过系统受保护凭据存储加密落盘;可选的记住密码记录使用独立的 Main-owned 加密存储,退出登录不会清除它,只有成功的未勾选密码登录才清除旧记录。未打包开发版只在内存持有会话且禁用记住密码,避免未签名 Electron 调试进程触发 macOS 钥匙串。Renderer 现有的短效公开 access-token 会话快照与持久化保持不变(旧版升级迁移时仅暂存既有刷新凭据,Main 成功接管后立即删除),账号密码不进入 Renderer 持久状态。
- Works Square 原生密码与短信登录均沿 Renderer → Host API → Electron Main → Works Square 链路完成。登录态按真实键盘、鼠标或触摸活动滑动续期;持续使用无需反复登录,连续 7 天未使用才清除会话并要求重新登录。刷新凭据始终只由 Electron Main 持有,并在正式安装包中通过系统受保护凭据存储加密落盘;可选的记住密码记录使用独立的 Main-owned 加密存储,退出登录不会清除它,只有成功的未勾选密码登录才清除旧记录。未打包开发版只在内存持有会话且禁用记住密码,避免未签名 Electron 调试进程触发 macOS 钥匙串。Renderer 现有的短效公开 access-token 会话快照与持久化保持不变(旧版升级迁移时仅暂存既有刷新凭据,Main 成功接管后立即删除),账号密码不进入 Renderer 持久状态。
- AI 编程发布只经过 Main-owned Host API:Renderer 仅提交本地项目标识、非敏感作品资料和有界封面 DTO;Main 持有源码快照、本地 npm/Vite 构建、精确产物预检、双归档、Works Token、版本生成、幂等重试和安全状态投影。发布构建同时提供 Main-owned `ReleaseJob` 的 start/progress/status/cancel 契约,同一项目串行执行并支持取消;异步 Job 的扫描、依赖安装、构建和双归档均在独立 `utilityProcess` 中以流式文件处理,Main 只接收进度、摘要和契约,旧的同步提交接口继续兼容已有客户端。首次项目 create 使用 `/api/projects/with-cover` multipart 原子写入资料与封面;已有项目只提交版本,状态竞态会固定失败并要求重新确认,不执行无条件 metadata PATCH 或封面替换。项目的 Vite config/plugins 会以当前桌面用户权限执行,因此该链路只适用于用户信任的本地项目,不是 sandbox。
- AI 编程项目配置只以项目内 `.makelore/project.json` 为准;项目文件和会话主数据保持本地,问答观察快照按个人资料同步规则单向上行。Main 不探测、读取或迁移 `.niancode` 与 `.opencode` 项目数据。
- AI 绘画 Renderer 只调用 Main-owned Host API;Main 负责 Works Square Token 刷新、Workspace 所属的持久 Agent Session、稳定命令身份、有界 Run 查询、可恢复事件订阅与契约映射,并通过本机 Host API 的 SSE 投影同步表单、任务和资产状态。切换 Workspace 只重连对应流;注销或退出时关闭本地流,不删除服务端持久 Session。远端 Token、Provider Prompt 与存储地址不进入 Renderer。
-22
View File
@@ -27,7 +27,6 @@ import {
getRememberedPasswordState,
updateRememberedPassword,
} from '../../services/remembered-password';
import { startPlatformAuthorization } from '../../services/platform-auth';
type PasswordLoginInput = {
username?: unknown;
@@ -336,22 +335,6 @@ async function handlePasswordLogin(
});
}
async function handlePlatformAuthorizationStart(
req: IncomingMessage,
res: ServerResponse,
): Promise<void> {
// Keep the route body intentionally empty: the Main process owns the OIDC
// client configuration and all PKCE state. The renderer only receives a
// browser URL and never handles a client secret.
readExactJsonObject(await parseJsonBody<Record<string, unknown>>(req), []);
const authorization = await startPlatformAuthorization();
sendJson(res, 200, {
success: true,
requestId: authorization.requestId,
authorizationUrl: authorization.authorizationUrl,
});
}
async function handleRememberedPassword(res: ServerResponse): Promise<void> {
const state = await getRememberedPasswordState();
res.setHeader('Cache-Control', 'no-store');
@@ -808,11 +791,6 @@ export async function handleAuthRoutes(
return true;
}
if (url.pathname === '/api/auth/platform/start' && req.method === 'POST') {
await handlePlatformAuthorizationStart(req, res);
return true;
}
if (url.pathname === '/api/auth/remembered-password' && req.method === 'GET') {
await handleRememberedPassword(res);
return true;
+4 -20
View File
@@ -2,11 +2,8 @@ export const NIANCODE_APP_PROTOCOL = 'niancode';
export type NianCodeDeepLink = {
type: 'desktop-auth-callback';
/** Legacy desktop auth callbacks carry a request id. OIDC callbacks use state. */
requestId?: string;
requestId: string;
url: string;
code?: string;
state?: string;
} | { type: 'cloud-agent'; slug: string; url: string }
| { type: 'teacher-preview'; draftRevision: number; url: string };
@@ -32,7 +29,6 @@ const SENSITIVE_QUERY_KEYS = new Set([
'device_secret',
'token',
]);
const AUTH_CALLBACK_QUERY_KEYS = new Set(['request_id', 'code', 'state']);
export function parseNianCodeDeepLinkUrl(rawUrl: string): NianCodeDeepLink | null {
let url: URL;
@@ -71,27 +67,15 @@ export function parseNianCodeDeepLinkUrl(rawUrl: string): NianCodeDeepLink | nul
}
}
if ([...url.searchParams.keys()].some((key) => !AUTH_CALLBACK_QUERY_KEYS.has(key))) {
const requestId = url.searchParams.get('request_id')?.trim();
if (!requestId || requestId.length > 128) {
return null;
}
const requestId = url.searchParams.get('request_id')?.trim() || undefined;
if (requestId && requestId.length > 128) return null;
const code = url.searchParams.get('code')?.trim() || undefined;
const state = url.searchParams.get('state')?.trim() || undefined;
if (Boolean(code) !== Boolean(state) || (code && code.length > 4096) || (state && state.length > 512)) {
return null;
}
// The platform OIDC redirect is registered as niancode://auth/callback and
// therefore returns code/state without the legacy request_id parameter.
if (!requestId && !(code && state)) return null;
return {
type: 'desktop-auth-callback',
...(requestId ? { requestId } : {}),
requestId,
url: rawUrl,
...(code ? { code, state } : {}),
};
}
+2 -60
View File
@@ -65,7 +65,6 @@ import { createReleaseUtilityPreparer } from '../services/release-utility-proces
import { createStaticArtifactSnapshot } from '../services/static-release-server';
import {
consumeWorksSquareStartupRuntimeCleanupRequired,
commitWorksSquareSessionFromTokenPayload,
getWorksSquareSessionRestoreStatus,
getWorksSquareSessionSnapshot,
initializeWorksSquareSession,
@@ -74,11 +73,7 @@ import {
} from '../services/works-square-session';
import { shouldUseSecureWorksSquareSessionPersistence } from '../services/works-square-session-persistence-policy';
import { initializeRememberedPassword } from '../services/remembered-password';
import {
clearManagedWorksSquareRuntimeBestEffort,
ensureManagedWorksSquareRuntimeClean,
} from '../services/works-square-runtime';
import { completePlatformAuthorization } from '../services/platform-auth';
import { clearManagedWorksSquareRuntimeBestEffort } from '../services/works-square-runtime';
import { WorksSquareDesignWorkspace } from '../image-workspace/works-square-workspace';
import type { DesignWorkspaceModule } from '../image-workspace/module';
import {
@@ -212,12 +207,6 @@ let releaseJobs: ReleaseJobManager | null = null;
let codingProducts: CodingProductComposition | null = null;
let windowIpcBindings: ReturnType<typeof registerIpcHandlers> | null = null;
let unsubscribeAuthSession: (() => void) | null = null;
let platformAuthReady = false;
let queuedPlatformAuthCallback: {
requestId: string | null;
code: string;
state: string;
} | null = null;
const mainWindowFocusState = createMainWindowFocusState();
const quitLifecycleState = createQuitLifecycleState();
const launchDeepLinkUrl = findNianCodeDeepLinkUrl(process.argv);
@@ -376,33 +365,6 @@ function requestMainWindowFocus(reason: string): void {
logger.debug(`Main window is not ready yet; deferring focus for ${reason}`);
}
function completePlatformAuthCallback(callback: {
requestId: string | null;
code: string;
state: string;
}): void {
void (async () => {
// Match the password/mobile login path: clean the previous account's
// derived runtime before making the new account active. Keeping the
// authorization pending until cleanup succeeds lets the user retry after
// a transient local cleanup failure.
await ensureManagedWorksSquareRuntimeClean({
codingProducts: codingProducts ?? undefined,
imageWorkspace: imageWorkspaceModule ?? undefined,
});
const payload = await completePlatformAuthorization(
callback.requestId,
callback.code,
callback.state,
);
await commitWorksSquareSessionFromTokenPayload(payload);
requestMainWindowFocus('platform OIDC callback');
})().catch((error) => {
logger.warn('[auth] Platform OIDC callback was not completed', error);
requestMainWindowFocus('platform OIDC callback failure');
});
}
function handleAppDeepLinkActivation(rawUrl: string): boolean {
const deepLink = parseNianCodeDeepLinkUrl(rawUrl);
if (!deepLink) {
@@ -416,21 +378,7 @@ function handleAppDeepLinkActivation(rawUrl: string): boolean {
queueTeacherPreviewRevision(deepLink.draftRevision);
mainWindow?.webContents.send('navigate', '/coding-teacher-preview?draftRevision=' + deepLink.draftRevision);
} else {
if (deepLink.code && deepLink.state) {
const callback = {
requestId: deepLink.requestId ?? null,
code: deepLink.code,
state: deepLink.state,
};
if (platformAuthReady) {
completePlatformAuthCallback(callback);
} else {
queuedPlatformAuthCallback = callback;
logger.debug('[auth] Queued platform OIDC callback until session restore is ready');
}
} else {
logger.info(`Received Makelore app link: type=${deepLink.type}, request_id=${deepLink.requestId ?? 'none'}`);
}
logger.info(`Received Makelore app link: type=${deepLink.type}, request_id=${deepLink.requestId}`);
}
requestMainWindowFocus('app deep link');
return true;
@@ -716,12 +664,6 @@ async function initialize(): Promise<void> {
}, 'expired persisted session during startup');
});
}
platformAuthReady = true;
if (queuedPlatformAuthCallback) {
const callback = queuedPlatformAuthCallback;
queuedPlatformAuthCallback = null;
completePlatformAuthCallback(callback);
}
if (!isE2EMode) {
projectProgressSync = createProjectProgressSync(codingProjectStore);
const activateProgrammingServices = (): void => {
-179
View File
@@ -1,179 +0,0 @@
import { createHash, randomBytes, randomUUID } from 'node:crypto';
import { WORKS_SQUARE_CONFIG } from '../api/works-config';
import { proxyAwareFetch } from '../utils/proxy-fetch';
import type { WorksSquareTokenPayload } from './works-square-session';
const DEFAULT_CLIENT_ID = 'makelore';
const DEFAULT_SCOPE = 'openid profile phone offline_access';
const REDIRECT_URI = 'niancode://auth/callback';
const STATE_TTL_MS = 10 * 60_000;
type PlatformAuthMetadata = {
authorization_endpoint: string;
token_endpoint: string;
};
type PendingAuthorization = {
state: string;
codeVerifier: string;
expiresAt: number;
};
const pendingAuthorizations = new Map<string, PendingAuthorization>();
let metadataPromise: Promise<PlatformAuthMetadata> | null = null;
function configuredIssuer(): string {
const raw = (process.env.PLATFORM_AUTH_ISSUER || WORKS_SQUARE_CONFIG.apiBaseUrl).trim().replace(/\/+$/, '');
const parsed = new URL(raw);
if (!['http:', 'https:'].includes(parsed.protocol) || parsed.username || parsed.password || parsed.search || parsed.hash) {
throw new Error('PLATFORM_AUTH_ISSUER must be an absolute HTTP(S) URL without credentials or query parameters');
}
return parsed.toString().replace(/\/$/, '');
}
function configuredClientId(): string {
return process.env.PLATFORM_AUTH_CLIENT_ID?.trim() || DEFAULT_CLIENT_ID;
}
function configuredScope(): string {
return process.env.PLATFORM_AUTH_SCOPE?.trim() || DEFAULT_SCOPE;
}
function absoluteHttpUrl(value: unknown, field: string): string {
if (typeof value !== 'string' || !value.trim()) throw new Error(`OIDC discovery missing ${field}`);
const parsed = new URL(value);
if (!['http:', 'https:'].includes(parsed.protocol) || parsed.username || parsed.password) {
throw new Error(`OIDC discovery returned an invalid ${field}`);
}
return parsed.toString();
}
async function loadMetadata(): Promise<PlatformAuthMetadata> {
const issuer = configuredIssuer();
const response = await proxyAwareFetch(`${issuer}/.well-known/openid-configuration`, {
method: 'GET',
headers: { Accept: 'application/json' },
});
if (!response.ok) throw new Error(`OIDC discovery failed (${response.status})`);
const payload = await response.json() as Record<string, unknown>;
return {
authorization_endpoint: absoluteHttpUrl(payload.authorization_endpoint, 'authorization_endpoint'),
token_endpoint: absoluteHttpUrl(payload.token_endpoint, 'token_endpoint'),
};
}
async function getMetadata(): Promise<PlatformAuthMetadata> {
if (!metadataPromise) {
metadataPromise = loadMetadata().catch((error) => {
metadataPromise = null;
throw error;
});
}
return metadataPromise;
}
function takePendingAuthorization(
requestId: string | null,
returnedState: string,
): PendingAuthorization | null {
if (requestId) {
const pending = pendingAuthorizations.get(requestId);
pendingAuthorizations.delete(requestId);
return pending ?? null;
}
// The platform redirect is a fixed niancode:// URI and does not append our
// local request id. The state value is the OIDC correlation handle instead.
for (const [candidateId, pending] of pendingAuthorizations) {
if (pending.state === returnedState) {
pendingAuthorizations.delete(candidateId);
return pending;
}
}
return null;
}
function cleanupPendingAuthorizations(now = Date.now()): void {
for (const [requestId, pending] of pendingAuthorizations) {
if (pending.expiresAt <= now) pendingAuthorizations.delete(requestId);
}
}
function codeChallengeS256(verifier: string): string {
return createHash('sha256').update(verifier, 'ascii').digest('base64url');
}
function readTokenPayload(value: unknown): WorksSquareTokenPayload {
if (!value || typeof value !== 'object' || Array.isArray(value)) {
throw new Error('OIDC token endpoint returned an invalid response');
}
const payload = value as WorksSquareTokenPayload;
if (typeof payload.access_token !== 'string' || !payload.access_token.trim()) {
throw new Error('OIDC token endpoint did not return access_token');
}
return payload;
}
export async function startPlatformAuthorization(): Promise<{
requestId: string;
authorizationUrl: string;
}> {
cleanupPendingAuthorizations();
const metadata = await getMetadata();
const requestId = randomUUID();
const state = randomBytes(32).toString('base64url');
const codeVerifier = randomBytes(64).toString('base64url');
pendingAuthorizations.set(requestId, {
state,
codeVerifier,
expiresAt: Date.now() + STATE_TTL_MS,
});
const url = new URL(metadata.authorization_endpoint);
url.searchParams.set('client_id', configuredClientId());
url.searchParams.set('response_type', 'code');
url.searchParams.set('redirect_uri', REDIRECT_URI);
url.searchParams.set('scope', configuredScope());
url.searchParams.set('state', state);
url.searchParams.set('nonce', randomBytes(32).toString('base64url'));
url.searchParams.set('code_challenge', codeChallengeS256(codeVerifier));
url.searchParams.set('code_challenge_method', 'S256');
return { requestId, authorizationUrl: url.toString() };
}
export async function completePlatformAuthorization(
requestId: string | null,
code: string,
returnedState: string,
): Promise<WorksSquareTokenPayload> {
cleanupPendingAuthorizations();
const pending = takePendingAuthorization(requestId, returnedState);
if (!pending || pending.expiresAt <= Date.now()) throw new Error('OIDC authorization request expired');
if (pending.state !== returnedState) throw new Error('OIDC authorization state mismatch');
const metadata = await getMetadata();
const response = await proxyAwareFetch(metadata.token_endpoint, {
method: 'POST',
headers: { 'Content-Type': 'application/x-www-form-urlencoded', Accept: 'application/json' },
body: new URLSearchParams({
grant_type: 'authorization_code',
code,
redirect_uri: REDIRECT_URI,
client_id: configuredClientId(),
code_verifier: pending.codeVerifier,
}).toString(),
});
if (!response.ok) {
const detail = await response.text();
throw new Error(`OIDC token exchange failed (${response.status}): ${detail.slice(0, 180)}`);
}
return readTokenPayload(await response.json());
}
export function resetPlatformAuthorizationForTests(): void {
pendingAuthorizations.clear();
metadataPromise = null;
}
export const PLATFORM_AUTH_REDIRECT_URI = REDIRECT_URI;
+1 -8
View File
@@ -284,14 +284,7 @@ function App() {
useEffect(() => {
const unsubscribe = subscribeHostEvent('auth:session-changed', (session) => {
const auth = useAuthStore.getState();
auth.applyMainSession(session);
// A platform OIDC callback is committed by Main and only carries the
// session credentials. Reload the current account so the renderer gets
// the stable username and module permissions before routing.
if (session) {
void auth.init().catch(() => undefined);
}
useAuthStore.getState().applyMainSession(session);
});
return unsubscribe;
}, []);
-36
View File
@@ -6,7 +6,6 @@ import { Card, CardContent, CardHeader, CardTitle } from '@/components/ui/card';
import { Input } from '@/components/ui/input';
import { Label } from '@/components/ui/label';
import { hostApiFetch } from '@/lib/host-api';
import { invokeIpc } from '@/lib/api-client';
import { useAuthStore } from '@/stores/auth';
import { useProviderStore } from '@/stores/providers';
import logoSvg from '@/assets/logo.svg';
@@ -308,30 +307,6 @@ export function Login() {
}
};
const handlePlatformLogin = async () => {
if (!agreed || busy) return;
setSubmitError(null);
setSubmitting(true);
try {
const response = await hostApiFetch<{
success?: unknown;
authorizationUrl?: unknown;
}>('/api/auth/platform/start', {
method: 'POST',
cache: 'no-store',
body: JSON.stringify({}),
});
if (response.success !== true) throw new Error('平台登录暂时不可用,请稍后重试。');
const authorizationUrl = getSafeExternalUrl(response.authorizationUrl);
if (!authorizationUrl) throw new Error('平台登录地址无效,请稍后重试。');
await invokeIpc('shell:openExternal', authorizationUrl);
} catch (loginError) {
setSubmitError(loginError instanceof Error ? loginError.message : String(loginError));
} finally {
setSubmitting(false);
}
};
const handleSendCode = async () => {
if (
sendingCode
@@ -489,17 +464,6 @@ export function Login() {
</form>
)}
<Button
type="button"
variant="outline"
className="w-full"
disabled={!agreed || busy}
onClick={() => void handlePlatformLogin()}
>
{submitting && <Loader2 className="mr-2 h-4 w-4 animate-spin" />}
平台账号登录
</Button>
<label className="flex items-start gap-2 text-xs leading-5 text-muted-foreground">
<input type="checkbox" className="mt-1" checked={agreed} onChange={(event) => setAgreed(event.target.checked)} />
<span>
-10
View File
@@ -24,19 +24,9 @@ describe('NianCode app deep links', () => {
});
});
it('parses the platform OIDC redirect without inventing a request id', () => {
expect(parseNianCodeDeepLinkUrl('niancode://auth/callback?code=oauth-code&state=oauth-state')).toEqual({
type: 'desktop-auth-callback',
url: 'niancode://auth/callback?code=oauth-code&state=oauth-state',
code: 'oauth-code',
state: 'oauth-state',
});
});
it('rejects links that do not target the desktop auth callback', () => {
expect(parseNianCodeDeepLinkUrl('https://square.nianxx.cn/#desktop-auth?request_id=1')).toBeNull();
expect(parseNianCodeDeepLinkUrl('niancode://auth/callback')).toBeNull();
expect(parseNianCodeDeepLinkUrl('niancode://auth/callback?code=oauth-code')).toBeNull();
expect(parseNianCodeDeepLinkUrl('niancode://auth/callback?request_id=')).toBeNull();
expect(parseNianCodeDeepLinkUrl('niancode://auth/callback?request_id=1&access_token=secret')).toBeNull();
expect(parseNianCodeDeepLinkUrl('niancode://settings')).toBeNull();
-31
View File
@@ -21,16 +21,10 @@ const providerServiceMock = vi.hoisted(() => ({
deleteAccountApiKey: vi.fn(),
}));
const platformAuthMock = vi.hoisted(() => ({
startPlatformAuthorization: vi.fn(),
}));
vi.mock('@electron/services/providers/provider-service', () => ({
getProviderService: () => providerServiceMock,
}));
vi.mock('@electron/services/platform-auth', () => platformAuthMock);
function createResponse() {
const chunks: string[] = [];
const res = {
@@ -72,31 +66,6 @@ describe('auth host api routes', () => {
resetRememberedPasswordForTests();
providerServiceMock.deleteAccountApiKey.mockReset();
providerServiceMock.deleteAccountApiKey.mockResolvedValue(true);
platformAuthMock.startPlatformAuthorization.mockReset();
platformAuthMock.startPlatformAuthorization.mockResolvedValue({
requestId: 'request-1',
authorizationUrl: 'https://square.example.test/authorize?state=state-1',
});
});
it('starts platform OIDC in Main and returns only the browser authorization URL', async () => {
const response = createResponse();
const handled = await handleAuthRoutes(
createRequest('POST', {}),
response.res,
new URL('http://127.0.0.1:13210/api/auth/platform/start'),
{} as never,
);
expect(handled).toBe(true);
expect(response.statusCode).toBe(200);
expect(response.json()).toEqual({
success: true,
requestId: 'request-1',
authorizationUrl: 'https://square.example.test/authorize?state=state-1',
});
expect(platformAuthMock.startPlatformAuthorization).toHaveBeenCalledOnce();
});
it('projects a safe current-user identity and module access without exposing secrets', async () => {
+1 -34
View File
@@ -8,16 +8,11 @@ import { useProviderStore } from '@/stores/providers';
import { codingRecoveryAccount } from '@/lib/coding-login-recovery';
const hostApiFetchMock = vi.hoisted(() => vi.fn());
const invokeIpcMock = vi.hoisted(() => vi.fn());
vi.mock('@/lib/host-api', () => ({
hostApiFetch: (...args: unknown[]) => hostApiFetchMock(...args),
}));
vi.mock('@/lib/api-client', () => ({
invokeIpc: (...args: unknown[]) => invokeIpcMock(...args),
}));
const loginWithPassword = vi.fn();
const loginWithMobile = vi.fn();
const logout = vi.fn();
@@ -133,7 +128,6 @@ describe('Login page', () => {
useProviderStore.setState({ importUserModelConfig });
importUserModelConfig.mockResolvedValue(undefined);
logout.mockResolvedValue(undefined);
invokeIpcMock.mockResolvedValue(undefined);
hostApiFetchMock.mockImplementation(async (path: string) => {
if (path === '/api/auth/public-config') {
return {
@@ -159,7 +153,7 @@ describe('Login page', () => {
vi.useRealTimers();
});
it('shows native Chinese tabs with password login as the default and a platform login action', async () => {
it('shows native Chinese tabs with password login as the default and no browser authorization surface', async () => {
renderLogin();
await screen.findByRole('link', { name: '用户协议' });
@@ -174,36 +168,9 @@ describe('Login page', () => {
loginButton.compareDocumentPosition(rememberPasswordCheckbox)
& Node.DOCUMENT_POSITION_FOLLOWING,
).toBe(Node.DOCUMENT_POSITION_FOLLOWING);
expect(screen.getByRole('button', { name: '平台账号登录' })).toBeDisabled();
expect(screen.queryByText(/浏览器|微信|注册/)).not.toBeInTheDocument();
});
it('opens the platform authorization URL through Main after agreement', async () => {
hostApiFetchMock.mockImplementation(async (path: string) => {
if (path === '/api/auth/public-config') return { success: true, links: {} };
if (path === '/api/auth/remembered-password') return { success: true, available: false };
if (path === '/api/auth/platform/start') {
return { success: true, authorizationUrl: 'https://square.example.test/authorize?state=state-1' };
}
return { success: true };
});
renderLogin();
const agreement = await screen.findByRole('checkbox', { name: /我已阅读并同意/ });
fireEvent.click(agreement);
fireEvent.click(screen.getByRole('button', { name: '平台账号登录' }));
await waitFor(() => expect(invokeIpcMock).toHaveBeenCalledWith(
'shell:openExternal',
'https://square.example.test/authorize?state=state-1',
));
expect(hostApiFetchMock).toHaveBeenCalledWith('/api/auth/platform/start', {
method: 'POST',
cache: 'no-store',
body: JSON.stringify({}),
});
});
it('restores OS-protected password credentials and keeps remember password selected', async () => {
hostApiFetchMock.mockImplementation(async (path: string) => {
if (path === '/api/auth/public-config') return { success: true, links: {} };
-73
View File
@@ -1,73 +0,0 @@
import { beforeEach, describe, expect, it, vi } from 'vitest';
import {
completePlatformAuthorization,
resetPlatformAuthorizationForTests,
startPlatformAuthorization,
} from '@electron/services/platform-auth';
describe('platform OIDC authorization', () => {
beforeEach(() => {
vi.restoreAllMocks();
resetPlatformAuthorizationForTests();
vi.stubEnv('PLATFORM_AUTH_ISSUER', 'https://square.example.test');
vi.stubEnv('PLATFORM_AUTH_CLIENT_ID', 'makelore');
vi.stubGlobal('fetch', vi.fn());
});
it('uses discovery, state, nonce, and S256 PKCE for the public desktop client', async () => {
const fetchMock = vi.mocked(fetch);
fetchMock.mockResolvedValueOnce(new Response(JSON.stringify({
authorization_endpoint: 'https://square.example.test/api/auth/oauth/authorize',
token_endpoint: 'https://square.example.test/api/auth/oauth/token',
}), { status: 200 }));
const started = await startPlatformAuthorization();
const authorizationUrl = new URL(started.authorizationUrl);
expect(authorizationUrl.searchParams.get('client_id')).toBe('makelore');
expect(authorizationUrl.searchParams.get('redirect_uri')).toBe('niancode://auth/callback');
expect(authorizationUrl.searchParams.get('response_type')).toBe('code');
expect(authorizationUrl.searchParams.get('code_challenge_method')).toBe('S256');
expect(authorizationUrl.searchParams.get('code_challenge')).toMatch(/^[A-Za-z0-9_-]{43}$/);
expect(authorizationUrl.searchParams.get('state')).toMatch(/^[A-Za-z0-9_-]{43}$/);
expect(authorizationUrl.searchParams.get('nonce')).toMatch(/^[A-Za-z0-9_-]{43}$/);
expect(authorizationUrl.searchParams.has('request_id')).toBe(false);
fetchMock.mockResolvedValueOnce(new Response(JSON.stringify({
access_token: 'access-token',
refresh_token: 'refresh-token',
token_type: 'Bearer',
expires_in: 3600,
}), { status: 200 }));
const payload = await completePlatformAuthorization(
null,
'authorization-code',
authorizationUrl.searchParams.get('state')!,
);
expect(payload).toMatchObject({ access_token: 'access-token', refresh_token: 'refresh-token' });
const [, init] = fetchMock.mock.calls[1] as [string, RequestInit];
expect(init.method).toBe('POST');
const body = new URLSearchParams(String(init.body));
expect(body.get('grant_type')).toBe('authorization_code');
expect(body.get('code')).toBe('authorization-code');
expect(body.get('client_id')).toBe('makelore');
expect(body.get('redirect_uri')).toBe('niancode://auth/callback');
expect(body.get('code_verifier')).toMatch(/^[A-Za-z0-9_-]{86}$/);
expect(fetchMock).toHaveBeenCalledTimes(2);
});
it('consumes a callback state once', async () => {
const fetchMock = vi.mocked(fetch);
fetchMock.mockResolvedValueOnce(new Response(JSON.stringify({
authorization_endpoint: 'https://square.example.test/api/auth/oauth/authorize',
token_endpoint: 'https://square.example.test/api/auth/oauth/token',
}), { status: 200 }));
const started = await startPlatformAuthorization();
const state = new URL(started.authorizationUrl).searchParams.get('state')!;
fetchMock.mockResolvedValueOnce(new Response(JSON.stringify({ access_token: 'access-token' }), { status: 200 }));
await completePlatformAuthorization(null, 'authorization-code', state);
await expect(completePlatformAuthorization(null, 'authorization-code', state))
.rejects.toThrow('OIDC authorization request expired');
});
});