fix: 全维度审查修复(安全/正确性/性能/稳定性/客户端/前端)
安全 - /api/ziniao/** 五个匿名接口加管理员鉴权(此前可匿名换取任意员工店铺登录令牌) - 删除 Flask 遗留后门:默认密码建超管 + 每次启动写生产 users 表(服务端与客户端各一份) - 进度/详情接口归属过滤:新增 TaskProgressOwnershipSupport,11 模块 progress/light 与 /tasks/batch 接入,DTO 补 userId,前端 13 个查询封装补传(未传时后端不过滤,兼容旧端) - 代理提取链接(含账密)不再明文入日志(新增 common/util/SecretMasking) - 全局异常兜底不再回传原始异常信息;内部令牌比较改常量时间 - 登录加失败计数与锁定(10 次锁 15 分钟);品牌源文件下载加 SSRF 防护 - AdminApiGuardFilter 覆盖前缀从 2 扩到 15(开关默认 false,行为不变,为收紧做准备) - 生产关闭 springdoc/knife4j(/doc.html 匿名可读全部接口定义) 正确性 - 40901/40902 拆分:锁竞争不再被伪装成 success=true(此前客户端停止重试、分片静默丢失) - 假成功收敛:集采明细批量写失败改为抛出、去重 worker 异常标失败、4 个 worker 改判 success 字段、publish 空 ASIN 行参与批次 flush、巡店删除全失败带 error 上报 - 客户端心跳 discard 移入 finally(7 模块,失败路径不再留僵尸 RUNNING 任务) - 状态机条件更新:跟价停止循环、集采 activate/fail、imagevideo 归档回填、店铺匹配提交 性能 - 前端入口包 JS 1.05MB→204KB、CSS 355KB→10.7KB(Element Plus 改按需 + el-config-provider) - 载荷引用计数按指针里的 taskId 收敛(原 JSON 列 IN 全表扫且逐行调用) - 店铺明细多值批量 INSERT;快照 upsert 预载缓存;结果文件列改单条 UPDATE - 新增迁移 V120(补 3 个缺失索引)/V121(删 4 个被覆盖的冗余索引)/V122(URL 前缀索引) 稳定性 - 新增 common/util/ThreadPools 有界线程池替换 5 处无界队列(防堆积 OOM) - Redis 锁释放改 Lua 原子校验(原裸 delete 会误删他人已过期的锁) - imagevideo 加死节点接管;锁续期失败重试;调度池 4→16;openStream 全部加超时 - 事务内远程对象删除移到提交后;启动恢复锁按实例命名 客户端 - 不再 taskkill /f /im chrome.exe(改为按调试端口精准回收,不杀用户自己的浏览器) - 密码检测不再无条件杀紫鸟进程;品牌检测加全局互斥(代理池不再互相覆盖) - base_dir 统一到 exe 目录(原被 os.getcwd() 覆盖,日志/缓存会分裂两个目录) - 缓存加定时清理;图片下载加超时;mkstemp 句柄托管 测试 - 同步更新受影响的契约测试(构造器签名/条件更新/方法改名/新增接口方法等) - 修复 FaultInjectionTest 等 3 处 mock 未 stub 流式 read 导致的读循环 OOM - mvn test 2795 个测试全绿
This commit is contained in:
@@ -115,7 +115,7 @@
|
||||
</template>
|
||||
|
||||
<script setup lang="ts">
|
||||
import { computed, onMounted, ref } from 'vue'
|
||||
import { computed, onBeforeUnmount, onMounted, ref } from 'vue'
|
||||
import { ElMessage } from 'element-plus'
|
||||
import AmazonToolPageShell from '@/pages/amazon/components/AmazonToolPageShell.vue';
|
||||
import TaskCenterPanel from '@/shared/components/tasks/TaskCenterPanel.vue'
|
||||
@@ -359,7 +359,10 @@ async function submitCleanRun() {
|
||||
}
|
||||
ElMessage.success('数据去重完成')
|
||||
} catch (error) {
|
||||
ElMessage.error(error instanceof Error ? error.message : '去重失败')
|
||||
// 卸载导致的轮询中止不提示(组件已不可见)
|
||||
if (!disposed) {
|
||||
ElMessage.error(error instanceof Error ? error.message : '去重失败')
|
||||
}
|
||||
} finally {
|
||||
cleanRunning.value = false
|
||||
}
|
||||
@@ -369,9 +372,19 @@ async function submitCleanRun() {
|
||||
const DEDUPE_POLL_INTERVAL_MS = 2000
|
||||
const DEDUPE_POLL_TIMEOUT_MS = 10 * 60 * 1000
|
||||
|
||||
// 组件卸载标记:轮询在用户切页后仍会继续(最长 10 分钟),并往已卸载组件的 ref 写数据、
|
||||
// 触发全局确认框。卸载后立即中止轮询(服务端任务照常执行,结果在历史列表可查)。
|
||||
let disposed = false
|
||||
onBeforeUnmount(() => {
|
||||
disposed = true
|
||||
})
|
||||
|
||||
async function pollDedupeRunProgress(runId: string, onProgress?: (progress: DedupeRunProgressVo) => void): Promise<DedupeRunVo> {
|
||||
const deadline = Date.now() + DEDUPE_POLL_TIMEOUT_MS
|
||||
while (true) {
|
||||
if (disposed) {
|
||||
throw new Error('页面已离开,停止轮询')
|
||||
}
|
||||
const progress = await getDedupeRunProgress(runId)
|
||||
if (progress.status === 'not_found') {
|
||||
throw new Error('去重任务不存在或已过期')
|
||||
|
||||
@@ -768,10 +768,13 @@ function mergeHistoryProgressItems(incoming: PatrolDeleteHistoryItem[]) {
|
||||
cartRatios: next.cartRatios || item.cartRatios || [],
|
||||
};
|
||||
});
|
||||
// 判重改 Set:此前 merged.some(...) 是 O(n×m),历史条目越多每轮轮询越慢
|
||||
const mergedKeys = new Set(merged.map(historyItemKey));
|
||||
for (const item of incoming) {
|
||||
const key = historyItemKey(item);
|
||||
if (!merged.some((current) => historyItemKey(current) === key)) {
|
||||
if (!mergedKeys.has(key)) {
|
||||
merged.push(item);
|
||||
mergedKeys.add(key);
|
||||
}
|
||||
}
|
||||
historyItems.value = merged;
|
||||
|
||||
@@ -380,8 +380,15 @@ function activeLoopStorageKey() {
|
||||
function setStorageJson(key: string, value: unknown, shouldRemove: boolean) {
|
||||
if (typeof window === 'undefined') return
|
||||
try {
|
||||
if (shouldRemove) window.localStorage.removeItem(key)
|
||||
else window.localStorage.setItem(key, JSON.stringify(value))
|
||||
if (shouldRemove) {
|
||||
window.localStorage.removeItem(key)
|
||||
return
|
||||
}
|
||||
const next = JSON.stringify(value)
|
||||
// 内容未变则跳过写入:本函数在每轮轮询里对整份快照调用(可达数百 KB),
|
||||
// 同步 setItem 会阻塞主线程造成周期性卡顿;相同内容重复写盘没有意义
|
||||
if (window.localStorage.getItem(key) === next) return
|
||||
window.localStorage.setItem(key, next)
|
||||
} catch {
|
||||
/* quota */
|
||||
}
|
||||
|
||||
@@ -370,9 +370,13 @@ function setStorageJson(key: string, value: unknown, shouldRemove: boolean) {
|
||||
try {
|
||||
if (shouldRemove) {
|
||||
window.localStorage.removeItem(key)
|
||||
} else {
|
||||
window.localStorage.setItem(key, JSON.stringify(value))
|
||||
return
|
||||
}
|
||||
const next = JSON.stringify(value)
|
||||
// 内容未变则跳过写入:本函数在每轮轮询里对整份快照调用(可达数百 KB),
|
||||
// 同步 setItem 会阻塞主线程造成周期性卡顿
|
||||
if (window.localStorage.getItem(key) === next) return
|
||||
window.localStorage.setItem(key, next)
|
||||
} catch {
|
||||
/* quota */
|
||||
}
|
||||
|
||||
@@ -458,12 +458,16 @@ function withQueryAsinFallback<T extends QueryAsinHistoryItem | QueryAsinShopQue
|
||||
item: T,
|
||||
fallback?: QueryAsinShopQueueItem | QueryAsinHistoryItem | null,
|
||||
) {
|
||||
const queryAsins = hasQueryAsins(item)
|
||||
? readQueryAsins(item)
|
||||
: readQueryAsins(fallback || undefined);
|
||||
// 已有 queryAsins 时直接返回原对象:本函数在每轮轮询里对全量历史调用,
|
||||
// 无条件 { ...item } 会让下游历史抽屉的全部卡片因 props 变化而每轮重渲染
|
||||
if (hasQueryAsins(item)) {
|
||||
return item;
|
||||
}
|
||||
const fallbackAsins = readQueryAsins(fallback || undefined);
|
||||
const resolved = fallbackAsins.length ? fallbackAsins : fallbackQueryAsinsForShop(item.shopName);
|
||||
return {
|
||||
...item,
|
||||
queryAsins: queryAsins.length ? queryAsins : fallbackQueryAsinsForShop(item.shopName),
|
||||
queryAsins: resolved,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -689,10 +693,13 @@ function mergeHistoryProgressItems(incoming: QueryAsinHistoryItem[]) {
|
||||
queryAsins,
|
||||
};
|
||||
});
|
||||
// 判重改 Set:此前 merged.some(...) 是 O(n×m),历史 500 条 × 每轮 20 条即 1 万次比较
|
||||
const mergedKeys = new Set(merged.map(historyItemKey));
|
||||
for (const item of incoming) {
|
||||
const key = historyItemKey(item);
|
||||
if (!merged.some((current) => historyItemKey(current) === key)) {
|
||||
if (!mergedKeys.has(key)) {
|
||||
merged.push(withQueryAsinFallback(item));
|
||||
mergedKeys.add(key);
|
||||
}
|
||||
}
|
||||
historyItems.value = merged;
|
||||
|
||||
@@ -139,7 +139,7 @@
|
||||
<div class="kv-row"><span class="kv-key">进度信息</span><span class="kv-val">{{ latestMessage(detailItem) || '-' }}</span></div>
|
||||
<template v-if="resultFiles(detailItem).length">
|
||||
<div class="kv-section">结果文件</div>
|
||||
<div v-for="(url, index) in resultFiles(detailItem)" :key="index" class="kv-row">
|
||||
<div v-for="(url, index) in resultFiles(detailItem)" :key="url" class="kv-row">
|
||||
<span class="kv-key">文件 {{ index + 1 }}</span>
|
||||
<a class="kv-val link" :href="url" target="_blank" rel="noopener">{{ url }}</a>
|
||||
</div>
|
||||
@@ -226,6 +226,10 @@ function statusClass(status?: number | string) {
|
||||
|
||||
let autoTimer: number | null = null
|
||||
let refreshTimer: number | null = null
|
||||
// 导出轮询用独立计时器:此前与自动刷新共用 autoTimer,两条链互相覆盖,必有一条无法被 cleanup 清掉
|
||||
let exportTimer: number | null = null
|
||||
// 组件已卸载标记:轮询链的异步回调在卸载后仍会续链(切页后继续打接口)
|
||||
let disposed = false
|
||||
|
||||
function uid() {
|
||||
const raw = typeof window === 'undefined' ? '' : window.localStorage.getItem('uid') || ''
|
||||
@@ -567,6 +571,10 @@ function pollExport(bridge: NonNullable<ReturnType<typeof getPywebviewApi>>, fil
|
||||
let count = 0
|
||||
const maxAttempts = 60
|
||||
const tick = async () => {
|
||||
if (disposed) {
|
||||
resolve(null)
|
||||
return
|
||||
}
|
||||
count += 1
|
||||
try {
|
||||
const res = await bridge.vc_query_export!(fileId)
|
||||
@@ -584,7 +592,7 @@ function pollExport(bridge: NonNullable<ReturnType<typeof getPywebviewApi>>, fil
|
||||
resolve(null)
|
||||
return
|
||||
}
|
||||
autoTimer = window.setTimeout(tick, 2000)
|
||||
exportTimer = window.setTimeout(tick, 2000)
|
||||
}
|
||||
void tick()
|
||||
})
|
||||
@@ -601,8 +609,12 @@ function scheduleAutoRefresh() {
|
||||
autoTimer = null
|
||||
}
|
||||
autoTimer = window.setTimeout(async () => {
|
||||
if (disposed) {
|
||||
return
|
||||
}
|
||||
await loadTasks(currentPage.value || 1)
|
||||
if (currentTasks.value.some((item) => isBusy(item.status))) {
|
||||
// 卸载后不得再续链:异步回调返回时组件可能已销毁,续链会持续打接口
|
||||
if (!disposed && currentTasks.value.some((item) => isBusy(item.status))) {
|
||||
scheduleAutoRefresh()
|
||||
}
|
||||
}, 3000)
|
||||
@@ -616,10 +628,15 @@ function startPolling() {
|
||||
}
|
||||
|
||||
function cleanup() {
|
||||
disposed = true
|
||||
if (autoTimer) {
|
||||
window.clearTimeout(autoTimer)
|
||||
autoTimer = null
|
||||
}
|
||||
if (exportTimer) {
|
||||
window.clearTimeout(exportTimer)
|
||||
exportTimer = null
|
||||
}
|
||||
if (refreshTimer) {
|
||||
window.clearInterval(refreshTimer)
|
||||
refreshTimer = null
|
||||
|
||||
@@ -817,10 +817,13 @@ function mergeHistoryProgressItems(incoming: WithdrawHistoryItem[]) {
|
||||
...next,
|
||||
};
|
||||
});
|
||||
// 判重改 Set:此前 merged.some(...) 是 O(n×m),历史条目越多每轮轮询越慢
|
||||
const mergedKeys = new Set(merged.map(historyItemKey));
|
||||
for (const item of incoming) {
|
||||
const key = historyItemKey(item);
|
||||
if (!merged.some((current) => historyItemKey(current) === key)) {
|
||||
if (!mergedKeys.has(key)) {
|
||||
merged.push(withWithdrawFallback(item));
|
||||
mergedKeys.add(key);
|
||||
}
|
||||
}
|
||||
historyItems.value = merged;
|
||||
|
||||
@@ -23,6 +23,7 @@
|
||||
</button>
|
||||
</div>
|
||||
<div class="update-hint">{{ hint }}</div>
|
||||
<UpdateLogList :entries="changelog" />
|
||||
<UpdateProgressBar :progress="progress" />
|
||||
<div v-if="hasUpdate || canDownload" style="margin-top: 4px;">
|
||||
<button type="button" class="btn-download-update" :disabled="updating" @click="doUpdate">
|
||||
@@ -64,13 +65,14 @@ import { restoreLoginUser } from '@/shared/auth/ensure-auth'
|
||||
import { getCurrentUserAppColumnRaw, readCachedAppColumnPermissions, type PermissionMenuItem } from '@/shared/api/permission'
|
||||
import { useVersionUpdate } from '@/shared/composables/useVersionUpdate'
|
||||
import UpdateProgressBar from '@/shared/components/UpdateProgressBar.vue'
|
||||
import UpdateLogList from '@/shared/components/UpdateLogList.vue'
|
||||
import NotificationBell from '@/shared/components/NotificationBell.vue'
|
||||
import { resolvePageHref } from '@/shared/page-prefix'
|
||||
|
||||
const username = ref('')
|
||||
const updatePanel = ref(false)
|
||||
const toastText = ref('')
|
||||
const { checking, updating, currentVersion, hasUpdate, canDownload, hint, checked, progress, runCheck, doUpdate } =
|
||||
const { checking, updating, currentVersion, hasUpdate, canDownload, hint, checked, progress, changelog, runCheck, doUpdate } =
|
||||
useVersionUpdate()
|
||||
|
||||
// 桌面端原 Flask /logout 已随瘦身下线:统一跳登录页并清本地 token(/login?logout=1)
|
||||
|
||||
@@ -526,6 +526,13 @@ type VoiceStatusType = 'info' | 'success' | 'error'
|
||||
const IMAGE_VIDEO_TASK_POLL_DELAY_MS = 5000
|
||||
const IMAGE_VIDEO_TASK_MAX_POLLS = 720
|
||||
|
||||
/**
|
||||
* 组件卸载标记:本页有两类长轮询(组装结果、Coze 异步任务,后者最长 720 次 × 5 秒 = 1 小时)。
|
||||
* 轮询回调在卸载后仍会「请求返回 → 续挂下一轮」,仅靠 onBeforeUnmount 清当前计时器挡不住
|
||||
* 在途请求,必须用标记在每次续链前判定。
|
||||
*/
|
||||
let disposed = false
|
||||
|
||||
type AssetState = {
|
||||
fileName: string
|
||||
previewUrl: string
|
||||
@@ -1002,6 +1009,10 @@ function isTerminalImageVideoTask(task: ImageVideoAsyncTaskVo) {
|
||||
async function waitForImageVideoTask(ticket: ImageVideoAsyncTaskVo): Promise<unknown> {
|
||||
let task = ticket
|
||||
for (let pollCount = 0; pollCount < IMAGE_VIDEO_TASK_MAX_POLLS; pollCount += 1) {
|
||||
if (disposed) {
|
||||
// 组件已卸载:停止轮询(否则切页后仍会每 5 秒打接口,最长 1 小时)
|
||||
throw new Error('页面已离开,停止轮询')
|
||||
}
|
||||
if (task.status === 'SUCCESS') return task.result
|
||||
if (isTerminalImageVideoTask(task)) {
|
||||
throw new Error(task.errorMessage || 'Coze task failed')
|
||||
@@ -1307,6 +1318,11 @@ async function pollAssemblyResult(tab: WorkspaceTab, taskId: number) {
|
||||
ElMessage.warning('Coze 执行结果查询超时,请稍后通过 execute_id 查看')
|
||||
return
|
||||
}
|
||||
if (disposed) {
|
||||
// 卸载瞬间请求在途时,回调返回后会重新挂表;此处判定保证卸载后不再续链
|
||||
assembly.polling = false
|
||||
return
|
||||
}
|
||||
assembly.pollTimer = window.setTimeout(() => {
|
||||
void pollAssemblyResult(tab, taskId)
|
||||
}, IMAGE_VIDEO_TASK_POLL_DELAY_MS)
|
||||
@@ -1791,6 +1807,7 @@ onMounted(() => {
|
||||
})
|
||||
|
||||
onBeforeUnmount(() => {
|
||||
disposed = true
|
||||
stopAssemblyPolling('remake')
|
||||
stopAssemblyPolling('imageToVideo')
|
||||
})
|
||||
|
||||
@@ -2,6 +2,40 @@
|
||||
<div class="legacy-login-root">
|
||||
<header class="header">
|
||||
<span class="header-title">数富AI</span>
|
||||
<!-- 版本更新入口固定右上角:桌面端自动下载安装;网页形态降级为下载最新安装包 -->
|
||||
<div class="login-header-right">
|
||||
<div class="login-update">
|
||||
<button type="button" class="link-update" @click="toggleUpdate">
|
||||
<svg viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
|
||||
<path d="M21 12a9 9 0 1 1-2.64-6.36"></path>
|
||||
<path d="M21 3v6h-6"></path>
|
||||
</svg>
|
||||
更新版本
|
||||
</button>
|
||||
<div v-if="updateOpen" class="update-panel">
|
||||
<div class="update-panel-title">软件更新</div>
|
||||
<div class="update-row"><span>当前版本</span><b>{{ currentVersion || '—' }}</b></div>
|
||||
<div class="update-row"><span>最新版本</span><b>{{ latestVersion || '—' }}</b></div>
|
||||
<div class="update-actions">
|
||||
<button type="button" class="btn-mini" :disabled="checking" @click="runCheck">
|
||||
{{ checking ? '检测中...' : '检测' }}
|
||||
</button>
|
||||
<button
|
||||
v-if="hasUpdate || canDownload"
|
||||
type="button"
|
||||
class="btn-mini btn-mini-green"
|
||||
:disabled="updating"
|
||||
@click="doUpdate"
|
||||
>
|
||||
{{ updating ? '更新中...' : '立即更新' }}
|
||||
</button>
|
||||
</div>
|
||||
<div class="update-hint">{{ hint }}</div>
|
||||
<UpdateLogList :entries="changelog" />
|
||||
<UpdateProgressBar :progress="progress" />
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</header>
|
||||
|
||||
<div class="login-box">
|
||||
@@ -59,38 +93,6 @@
|
||||
{{ loggingIn ? '登录中...' : '登录' }}
|
||||
</button>
|
||||
</form>
|
||||
|
||||
<!-- 版本更新:桌面端自动下载安装;网页形态降级为下载最新安装包 -->
|
||||
<div class="login-update">
|
||||
<button type="button" class="link-update" @click="toggleUpdate">
|
||||
<svg viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
|
||||
<path d="M21 12a9 9 0 1 1-2.64-6.36"></path>
|
||||
<path d="M21 3v6h-6"></path>
|
||||
</svg>
|
||||
更新版本
|
||||
</button>
|
||||
<div v-if="updateOpen" class="update-panel">
|
||||
<div class="update-panel-title">软件更新</div>
|
||||
<div class="update-row"><span>当前版本</span><b>{{ currentVersion || '—' }}</b></div>
|
||||
<div class="update-row"><span>最新版本</span><b>{{ latestVersion || '—' }}</b></div>
|
||||
<div class="update-actions">
|
||||
<button type="button" class="btn-mini" :disabled="checking" @click="runCheck">
|
||||
{{ checking ? '检测中...' : '检测' }}
|
||||
</button>
|
||||
<button
|
||||
v-if="hasUpdate || canDownload"
|
||||
type="button"
|
||||
class="btn-mini btn-mini-green"
|
||||
:disabled="updating"
|
||||
@click="doUpdate"
|
||||
>
|
||||
{{ updating ? '更新中...' : '立即更新' }}
|
||||
</button>
|
||||
</div>
|
||||
<div class="update-hint">{{ hint }}</div>
|
||||
<UpdateProgressBar :progress="progress" />
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
@@ -103,6 +105,7 @@ import { KICK_NOTICE_KEY } from '@/shared/auth/kick-handler'
|
||||
import { useVersionUpdate } from '@/shared/composables/useVersionUpdate'
|
||||
import { clearApiSecretCache } from '@/shared/utils/api-secret-store'
|
||||
import UpdateProgressBar from '@/shared/components/UpdateProgressBar.vue'
|
||||
import UpdateLogList from '@/shared/components/UpdateLogList.vue'
|
||||
|
||||
const router = useRouter()
|
||||
|
||||
@@ -134,6 +137,7 @@ const {
|
||||
hint,
|
||||
checked,
|
||||
progress,
|
||||
changelog,
|
||||
runCheck,
|
||||
doUpdate,
|
||||
} = useVersionUpdate()
|
||||
@@ -682,10 +686,15 @@ body {
|
||||
cursor: not-allowed;
|
||||
}
|
||||
|
||||
/* 版本更新入口与面板 */
|
||||
/* 版本更新入口与面板:入口固定顶栏右上角,面板在该入口下方浮层展开
|
||||
(类名加 login- 前缀,避免与首页同名全局样式互相覆盖) */
|
||||
.login-header-right {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.login-update {
|
||||
margin-top: 14px;
|
||||
text-align: center;
|
||||
position: relative;
|
||||
}
|
||||
|
||||
.link-update {
|
||||
@@ -713,11 +722,16 @@ body {
|
||||
}
|
||||
|
||||
.update-panel {
|
||||
margin-top: 10px;
|
||||
position: absolute;
|
||||
top: 34px;
|
||||
right: 0;
|
||||
z-index: 20;
|
||||
width: 300px;
|
||||
padding: 12px 14px;
|
||||
background: #f6fafd;
|
||||
background: #ffffff;
|
||||
border: 1px solid #d5e6f2;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 8px 24px rgba(20, 50, 80, 0.16);
|
||||
text-align: left;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user