|
|
2449a27eb5
|
refactor: CSP nonce替代unsafe-inline, HSTS始终启用, router/api拆分, 管理后台+用户设置页拆分, DB健康降级, 时区配置, UID统一解析, CI接入
CI / Lint + Build (push) Has been cancelled
审计修复:
- CSP: unsafe-inline移除, nonce替代; unsafe-eval保留供Vditor使用
- HSTS: 始终启用(不再依赖release模式)
- Controller Exp: common.GetGinExp包装, 不再直接读context
- UID解析: common.ParseUIDParam统一, follow/admin controller改用
重构:
- router/api.go(198行)拆为7个域文件: auth/settings/posts/comments/reactions/social/studio
- 管理后台站点设置: 单页拆为4个子页(brand/security/registration/content)+子菜单
- 前台用户设置页: 1201行拆为6个独立模板+6个独立JS文件
新增:
- DB健康检测中间件(middleware/db_health.go): 5s ping+降级页面
- 时区配置: config.yaml server.timezone→time.Local初始化
- .gitea/workflows/ci.yml: strict模式CI流水线
|
2026-06-22 03:06:24 +08:00 |
|
|
|
97adf54d6d
|
fix: golangci-lint 零告警通过 (57→0) + gofumpt/goimports 全量格式化
## CI 修复 (P0/P1)
P0 — 编译阻塞:
- interfaces.go: postUseCase ISP 接口移除不用的 Create/Update/Delete
P1 — 必须修复:
- ST1000: 为 13 个包添加包注释 (common/config/model/service/...)
- ST1005: redis_store.go 全部错误消息改为小写开头
- errcheck (19处): defer Close()→闭包忽略, notifier.Create→_=, r.Run→检查error
- errorlint (9处): switch-on-error→errors.Is 链, ==→errors.Is
- ST1020/ST1022: 导出符号注释以符号名开头
P2 — 安全评审:
- gosec (12处): G203/G301/G304/G306 添加 nolint 注释并附理由
P3 — 清理:
- unused: 移除 hasUnicode/energyStore/current/energyAdminUseCase
- gofumpt + goimports 全量格式化 (35+ 文件)
|
2026-06-22 02:27:35 +08:00 |
|
|
|
a2e8242c21
|
chore: 全局包名路径从 metalab 更改为 mce
|
2026-06-21 16:55:46 +08:00 |
|
|
|
a0df66587b
|
fix: 修复关注/粉丝列表隐私检查假阳性导致本人也无法访问
- follow_repo.go: GetFollowListPublic 改用显式 WHERE uid=? 避免 GORM 主键解析潜在问题
- follow_service.go: GetFollowListPublic 失败时默认公开并记录日志,而非返回错误
- follow_controller.go: 错误兜底时 Accessible 默认 true,避免误锁用户
|
2026-06-01 20:22:50 +08:00 |
|
|
|
680df7371a
|
feat: 实现关注系统 + 通知侧边栏分类 TAB + 点赞聚合通知
- 新增关注系统:UserFollow 模型、FollowService(toggle/status/列表隐私控制)
- User 新增 FollowersCount/FollowingCount/FollowListPublic/NotifyPrefs 字段
- Space 页面增加四态关注按钮(关注/已关注/回关/已互粉)+ 粉丝/关注数链接
- 新增 /space/:uid/followers 和 /space/:uid/following 列表页
- 新增 NotifyFollow/NotifyLikeAggregated 通知类型
- ReactionService 点赞时写入 daily_like_summary,访问时生成聚合通知
- FollowService 关注时触发 NotifyFollow 通知
- 消息中心侧边栏升级为分类 TAB(全部/系统通知/@艾特/点赞/关注)
- NotificationService 新增 ListByCategory 按分类分页查询
|
2026-06-01 16:30:46 +08:00 |
|