feat(account-management): add upload and download cookie file buttons

- Add '上传Cookie文件' and '下载Cookie文件' buttons to account management page
- Implement frontend functionality for cookie file upload and download
- Add backend API endpoints for handling cookie file operations:
  - /uploadCookie: Handle cookie file upload with validation
  - /downloadCookie: Handle secure cookie file download
- Implement security measures to prevent path traversal attacks
- Add proper error handling and user feedback
- Maintain existing functionality while adding new features
This commit is contained in:
Deroino
2025-11-13 10:37:19 +08:00
parent 4ee6c2b09c
commit 4688c41b9b
2 changed files with 203 additions and 1 deletions
+121
View File
@@ -476,6 +476,127 @@ def postVideoBatch():
"data": None
}), 200
# Cookie文件上传API
@app.route('/uploadCookie', methods=['POST'])
def upload_cookie():
try:
if 'file' not in request.files:
return jsonify({
"code": 500,
"msg": "没有找到Cookie文件",
"data": None
}), 400
file = request.files['file']
if file.filename == '':
return jsonify({
"code": 500,
"msg": "Cookie文件名不能为空",
"data": None
}), 400
if not file.filename.endswith('.json'):
return jsonify({
"code": 500,
"msg": "Cookie文件必须是JSON格式",
"data": None
}), 400
# 获取账号信息
account_id = request.form.get('id')
platform = request.form.get('platform')
if not account_id or not platform:
return jsonify({
"code": 500,
"msg": "缺少账号ID或平台信息",
"data": None
}), 400
# 从数据库获取账号的文件路径
with sqlite3.connect(Path(BASE_DIR / "db" / "database.db")) as conn:
conn.row_factory = sqlite3.Row
cursor = conn.cursor()
cursor.execute('SELECT filePath FROM user_info WHERE id = ?', (account_id,))
result = cursor.fetchone()
if not result:
return jsonify({
"code": 500,
"msg": "账号不存在",
"data": None
}), 404
# 保存上传的Cookie文件到对应路径
cookie_file_path = Path(BASE_DIR / "cookiesFile" / result['filePath'])
cookie_file_path.parent.mkdir(parents=True, exist_ok=True)
file.save(str(cookie_file_path))
# 更新数据库中的账号信息(可选,比如更新更新时间)
# 这里可以根据需要添加额外的处理逻辑
return jsonify({
"code": 200,
"msg": "Cookie文件上传成功",
"data": None
}), 200
except Exception as e:
print(f"上传Cookie文件时出错: {str(e)}")
return jsonify({
"code": 500,
"msg": f"上传Cookie文件失败: {str(e)}",
"data": None
}), 500
# Cookie文件下载API
@app.route('/downloadCookie', methods=['GET'])
def download_cookie():
try:
file_path = request.args.get('filePath')
if not file_path:
return jsonify({
"code": 500,
"msg": "缺少文件路径参数",
"data": None
}), 400
# 验证文件路径的安全性,防止路径遍历攻击
cookie_file_path = Path(BASE_DIR / "cookiesFile" / file_path).resolve()
base_path = Path(BASE_DIR / "cookiesFile").resolve()
if not cookie_file_path.is_relative_to(base_path):
return jsonify({
"code": 500,
"msg": "非法文件路径",
"data": None
}), 400
if not cookie_file_path.exists():
return jsonify({
"code": 500,
"msg": "Cookie文件不存在",
"data": None
}), 404
# 返回文件
return send_from_directory(
directory=str(cookie_file_path.parent),
path=cookie_file_path.name,
as_attachment=True
)
except Exception as e:
print(f"下载Cookie文件时出错: {str(e)}")
return jsonify({
"code": 500,
"msg": f"下载Cookie文件失败: {str(e)}",
"data": None
}), 500
# 包装函数:在线程中运行异步函数
def run_async_function(type,id,status_queue):
match type: