fix: 修复在线更新暂存链路并增加全局 API 限流备底

- 新增 server/rate-limit.ts:进程内固定窗口限流器,无数据库写入
- server/app.ts 注册全局 preHandler,仅作用于 /api/*,超限返回 429 与 Retry-After
- 提取 isApiPath 统一 onSend、preHandler 与 404 的路径判断
- 更新任务冲突判定改用 ACTIVE_UPDATE_CONFLICT_SQL,staged/download 产物不再阻塞新任务
- cancelUpdateJob 调用补上 await,避免结果恒为 pending Promise
- server/cli/update.ts 增加特权工作区所有权校验与暂存路径重建逻辑
- 新增 tests/rate-limit.test.ts 与 tests/update-apply-staging.test.ts
This commit is contained in:
Qiufeng
2026-09-17 13:12:20 +08:00
parent 5afcd98ebd
commit ae8966baf6
12 changed files with 1145 additions and 71 deletions
+10 -3
View File
@@ -1049,14 +1049,21 @@ export default function UpdatePage({
<div>• 升级过程具备原子切换与自愈保护,若健康检查异常将自动回退至当前版本。</div>
</div>
<div className="tn-modal-actions-bar">
<Button variant="outline" onClick={() => setShowUpgradeModal(false)}>
稍后手动应用
{/* A staged download has no runner attached yet, so the
administrator can still discard it and free the slot. */}
<Button
variant="outline"
onClick={() => void cancelJob()}
loading={cancelling}
disabled={cancelling || actionBusy}
>
取消并清理
</Button>
<Button
theme="primary"
onClick={() => void startApply()}
loading={actionBusy}
disabled={actionBusy}
disabled={actionBusy || cancelling}
icon={<Zap size={16} />}
>
立即应用并重启