Commit Graph
3 Commits
Author SHA1 Message Date
TIANYAO ZHANG b9c79c8138 fix: revoke API keys on password rotation and audit key owners 2026-10-03 17:17:34 +08:00
senlinjun bf7858db74 docs(api): document /api/me/music, bilibili parts and personal-FM behavior from v1.14.0
- new /api/me/music section (per-user NetEase account linking, key-compatible)
- GET /api/music/bilibili/parts endpoint
- /api/player/:botId/fm note: prefers the caller's own linked NetEase account
2026-09-29 21:55:53 +08:00
senlinjun aab8a004ae feat(web): add API-key authentication for the REST API
- api_keys table + hashed key store (src/data/api-keys.ts), tsmb_-prefixed
  plaintext shown once, per-user cap of 20, lastUsedAt tracking
- requireAuth accepts Authorization: Bearer / X-API-Key headers as an
  alternative to the session cookie; key inherits the owner user's
  role/capabilities/bot scope
- csrf origin check skipped for key-only requests (no ambient credentials);
  requests that also carry the session cookie stay gated
- /api/keys management endpoints (session-only, guests excluded, keys
  themselves rejected) with audit logging
- user deletion / password reset cascade-revoke the user's keys
- Settings page: API key management section (create/copy-once/revoke)
- docs: README section + full endpoint reference in docs/API.md
2026-09-29 21:51:43 +08:00