Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5d02fa5769 | ||
|
|
526b2df8ea | ||
|
|
4f9629b089 | ||
|
|
36c2ed1361 | ||
|
|
755b82d2e5 | ||
|
|
0bdc812935 | ||
|
|
2de08f1358 | ||
|
|
91621df6c4 | ||
|
|
0690fe298c | ||
|
|
6a0d9e34dd |
@@ -140,7 +140,7 @@ curl --proto '=https' --tlsv1.2 -fsSL https://git.awaioi.com/awaioi/TallyNote/ra
|
|||||||
|
|
||||||
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
||||||
|
|
||||||
公网反代必须使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。
|
公网反代推荐使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。反代只需把域名转发到 TallyNote 端口并保留 `Host`、`X-Forwarded-Proto`;应用不会因为代理缺少或改写浏览器 `Origin` 而拦截登录。已认证写请求仍使用会话 Cookie 与 CSRF 令牌保护。
|
||||||
|
|
||||||
### 构建发布包
|
### 构建发布包
|
||||||
|
|
||||||
|
|||||||
+5
-2
@@ -1012,7 +1012,10 @@ validate_listen_port() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
validate_public_origin() {
|
validate_public_origin() {
|
||||||
local value=$1 authority host path_part origin_port suffix
|
# Keep the optional origin port defined under `set -u`. Origins without an
|
||||||
|
# explicit port (for example https://example.test) are valid and should
|
||||||
|
# proceed to the default-port handling below.
|
||||||
|
local value=$1 authority host path_part origin_port='' suffix
|
||||||
case "$value" in
|
case "$value" in
|
||||||
http://*|https://*) ;;
|
http://*|https://*) ;;
|
||||||
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
|
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
|
||||||
@@ -1074,7 +1077,7 @@ validate_existing_env() {
|
|||||||
mode_bits=$(stat_mode_bits "$file")
|
mode_bits=$(stat_mode_bits "$file")
|
||||||
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
|
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
|
||||||
local key key_count
|
local key key_count
|
||||||
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOWED_ORIGINS TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
||||||
key_count=$(env_key_count "$file" "$key")
|
key_count=$(env_key_count "$file" "$key")
|
||||||
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
|
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
ALTER TABLE update_jobs ADD COLUMN downloaded_bytes INTEGER;
|
||||||
|
ALTER TABLE update_jobs ADD COLUMN download_started_at INTEGER;
|
||||||
|
ALTER TABLE update_jobs ADD COLUMN download_speed_bps INTEGER;
|
||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "tallynote",
|
"name": "tallynote",
|
||||||
"version": "1.1.16",
|
"version": "1.1.24",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"packageManager": "pnpm@9.0.6",
|
"packageManager": "pnpm@9.0.6",
|
||||||
|
|||||||
@@ -190,6 +190,15 @@ recover_stale_state() {
|
|||||||
[[ "$state_job" =~ ^[0-9a-f-]{36}$ ]] || die 'update state job id is invalid'
|
[[ "$state_job" =~ ^[0-9a-f-]{36}$ ]] || die 'update state job id is invalid'
|
||||||
[[ "$state_old" == "$PREFIX/releases/"* && -d "$state_old" && ! -L "$state_old" ]] || die 'update state target is invalid'
|
[[ "$state_old" == "$PREFIX/releases/"* && -d "$state_old" && ! -L "$state_old" ]] || die 'update state target is invalid'
|
||||||
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
||||||
|
if [[ "$state_phase" == download && "$current_target" == "$state_old" ]]; then
|
||||||
|
# Downloading never changes the active release. If the runner was killed
|
||||||
|
# after the CLI staged its payload but before it removed the recovery
|
||||||
|
# marker, keep the request available for an idempotent retry. Treating
|
||||||
|
# every stale download marker as a failed apply would discard a usable
|
||||||
|
# staged payload and leave the browser showing a misleading failure.
|
||||||
|
clear_update_state || true
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
if [[ "$state_phase" == finalizing && "$current_target" != "$state_old" ]]; then
|
if [[ "$state_phase" == finalizing && "$current_target" != "$state_old" ]]; then
|
||||||
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
||||||
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
||||||
|
|||||||
@@ -195,6 +195,40 @@ grep -q -- '--finalize-job' "$runner_root/node.log"
|
|||||||
[[ ! -e "$runner_data/update-request.json" ]]
|
[[ ! -e "$runner_data/update-request.json" ]]
|
||||||
[[ ! -e "$runner_prefix/.update-state" ]]
|
[[ ! -e "$runner_prefix/.update-state" ]]
|
||||||
|
|
||||||
|
# A stale download marker must be recoverable without finalizing the staged
|
||||||
|
# download as a failed apply. The next runner invocation should retry the
|
||||||
|
# request and let the CLI preserve/refresh its staged workspace.
|
||||||
|
download_runner_root="$tmp/download-runner"
|
||||||
|
download_runner_prefix="$download_runner_root/prefix"
|
||||||
|
download_runner_data="$download_runner_root/data"
|
||||||
|
download_runner_tools="$download_runner_root/tools"
|
||||||
|
mkdir -p "$download_runner_prefix/releases/1.0.0/runtime/bin" "$download_runner_prefix/releases/1.0.0/dist/server/cli" "$download_runner_data" "$download_runner_tools"
|
||||||
|
ln -s "$download_runner_prefix/releases/1.0.0" "$download_runner_prefix/current"
|
||||||
|
# The request has already been consumed; only the stale download marker is
|
||||||
|
# left, which is the narrow recovery window covered by this fixture.
|
||||||
|
download_runner_prefix_physical=$(cd "$download_runner_prefix" && pwd -P)
|
||||||
|
download_runner_data_physical=$(cd "$download_runner_data" && pwd -P)
|
||||||
|
printf '%s\n' 'job_id=00000000-0000-4000-8000-000000000002' "old_target=$download_runner_prefix_physical/releases/1.0.0" 'phase=download' > "$download_runner_prefix/.update-state"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'printf "%s\n" "$*" >> "$TALLYNOTE_DOWNLOAD_NODE_TRACE"' 'exit 0' > "$download_runner_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
|
printf '%s\n' cli > "$download_runner_prefix/releases/1.0.0/dist/server/cli/update.js"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'case "${1:-}" in is-active) exit 0;; *) exit 0;; esac' > "$download_runner_tools/systemctl"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'if [[ "${1:-}" == "-f" ]]; then shift; [[ "${1:-}" == "--" ]] && shift; /bin/realpath "$1"; else /usr/bin/readlink "$@"; fi' > "$download_runner_tools/readlink"
|
||||||
|
cat >"$download_runner_tools/stat" <<'EOF'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
case "$*" in
|
||||||
|
*"-c %u"*|*"-f %u"*) printf '0\n' ;;
|
||||||
|
*"-c %a"*|*"-f %Lp"*) printf '600\n' ;;
|
||||||
|
*) /usr/bin/stat "$@" ;;
|
||||||
|
esac
|
||||||
|
EOF
|
||||||
|
chmod 755 "$download_runner_prefix/releases/1.0.0/runtime/bin/node" "$download_runner_tools/systemctl" "$download_runner_tools/readlink" "$download_runner_tools/stat"
|
||||||
|
download_runner_script="$download_runner_root/runner.sh"
|
||||||
|
sed "s#PATH=/usr/sbin:/usr/bin:/sbin:/bin#PATH=$download_runner_tools:/usr/sbin:/usr/bin:/sbin:/bin#" "$root/scripts/tallynote-update-runner.sh" > "$download_runner_script"
|
||||||
|
chmod 755 "$download_runner_script"
|
||||||
|
env EUID=0 TALLYNOTE_INSTALL_PREFIX="$download_runner_prefix_physical" TALLYNOTE_DATA_DIR="$download_runner_data_physical" TALLYNOTE_DOWNLOAD_NODE_TRACE="$download_runner_root/node.log" bash "$download_runner_script"
|
||||||
|
[[ ! -e "$download_runner_root/node.log" ]]
|
||||||
|
[[ ! -e "$download_runner_prefix/.update-state" ]]
|
||||||
|
|
||||||
# A RETURN trap installed by install_release must be cleared while its local
|
# A RETURN trap installed by install_release must be cleared while its local
|
||||||
# temporary variables still exist; otherwise set -u fails at the end of main.
|
# temporary variables still exist; otherwise set -u fails at the end of main.
|
||||||
release_fixture="$tmp/release-fixture"
|
release_fixture="$tmp/release-fixture"
|
||||||
@@ -253,7 +287,11 @@ ln -s "$wrapper_prefix/releases/1.0.0" "$wrapper_prefix/current"
|
|||||||
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
|
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
|
||||||
TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
# This fixture verifies release-relative execution and argument forwarding.
|
||||||
|
# Force the wrapper's non-root branch so the root CI runner does not need a
|
||||||
|
# real `tallynote` service account or a privileged runuser hand-off; that
|
||||||
|
# privilege boundary is validated by the production checks themselves.
|
||||||
|
env EUID=1000 TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
||||||
bash "$root/bin/tallynote-admin-init" --generate
|
bash "$root/bin/tallynote-admin-init" --generate
|
||||||
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
|
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
|
||||||
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
|
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
|
||||||
@@ -420,6 +458,9 @@ bash -c '
|
|||||||
stat_uid() { printf "0"; }
|
stat_uid() { printf "0"; }
|
||||||
stat_mode_bits() { printf "384"; }
|
stat_mode_bits() { printf "384"; }
|
||||||
validate_public_origin "http://[2001:db8::10]:3000"
|
validate_public_origin "http://[2001:db8::10]:3000"
|
||||||
|
# A standard HTTPS origin may omit its default port; this must remain valid
|
||||||
|
# under the installer strict unset-variable mode.
|
||||||
|
validate_public_origin "https://example.test"
|
||||||
' _ "$installer_lib"
|
' _ "$installer_lib"
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'TALLYNOTE_HOST=0.0.0.0' \
|
'TALLYNOTE_HOST=0.0.0.0' \
|
||||||
|
|||||||
+14
-15
@@ -119,7 +119,7 @@ function enforceUpdateCooldown(
|
|||||||
adminId: string,
|
adminId: string,
|
||||||
operation: "check" | "download" | "apply",
|
operation: "check" | "download" | "apply",
|
||||||
reply: FastifyReply,
|
reply: FastifyReply,
|
||||||
): void {
|
): number {
|
||||||
const state = updateRateState(database, adminId);
|
const state = updateRateState(database, adminId);
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
const previous = operation === "check" ? state.checkedAt : operation === "download" ? state.downloadedAt : state.appliedAt;
|
const previous = operation === "check" ? state.checkedAt : operation === "download" ? state.downloadedAt : state.appliedAt;
|
||||||
@@ -134,6 +134,7 @@ function enforceUpdateCooldown(
|
|||||||
if (operation === "check") state.checkedAt = now;
|
if (operation === "check") state.checkedAt = now;
|
||||||
else if (operation === "download") state.downloadedAt = now;
|
else if (operation === "download") state.downloadedAt = now;
|
||||||
else state.appliedAt = now;
|
else state.appliedAt = now;
|
||||||
|
return now;
|
||||||
}
|
}
|
||||||
|
|
||||||
function adminSelect(alias = ""): string {
|
function adminSelect(alias = ""): string {
|
||||||
@@ -647,19 +648,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
return payload;
|
return payload;
|
||||||
});
|
});
|
||||||
|
|
||||||
app.addHook("onRequest", async (request) => {
|
|
||||||
if (!unsafeMethods.has(request.method) || !request.url.startsWith("/api/")) return;
|
|
||||||
const origin = request.headers.origin;
|
|
||||||
const allowed = new Set([config.publicOrigin]);
|
|
||||||
if (!config.isProduction) {
|
|
||||||
allowed.add("http://127.0.0.1:5173");
|
|
||||||
allowed.add("http://localhost:5173");
|
|
||||||
}
|
|
||||||
if (typeof origin !== "string" || !allowed.has(origin)) {
|
|
||||||
throw new AppError(403, "ORIGIN_FORBIDDEN", "请求来源不受信任");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
app.setErrorHandler((error, request, reply) => {
|
app.setErrorHandler((error, request, reply) => {
|
||||||
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
||||||
if (error instanceof ZodError) {
|
if (error instanceof ZodError) {
|
||||||
@@ -946,6 +934,8 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||||
|
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||||
|
download_speed_bps AS downloadSpeedBps,
|
||||||
requested_at AS applyQueuedAt
|
requested_at AS applyQueuedAt
|
||||||
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
||||||
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||||
@@ -957,12 +947,15 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
});
|
});
|
||||||
|
|
||||||
app.post("/api/update/check", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
app.post("/api/update/check", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
||||||
|
const rateState = updateRateState(database.sqlite, request.auth!.admin.id);
|
||||||
|
const previousCheckedAt = rateState.checkedAt;
|
||||||
|
let reservedCheckedAt: number | null = null;
|
||||||
try {
|
try {
|
||||||
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
// Disabled/dev installs do not contact a release endpoint, so repeated
|
// Disabled/dev installs do not contact a release endpoint, so repeated
|
||||||
// checks are local status reads and should remain immediately usable.
|
// checks are local status reads and should remain immediately usable.
|
||||||
if (config.updateStrategy !== "disabled") {
|
if (config.updateStrategy !== "disabled") {
|
||||||
enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
reservedCheckedAt = enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
||||||
}
|
}
|
||||||
const result = await checkForUpdate(database.sqlite, config);
|
const result = await checkForUpdate(database.sqlite, config);
|
||||||
writeAudit(database.sqlite, {
|
writeAudit(database.sqlite, {
|
||||||
@@ -981,6 +974,10 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
reply.header("Cache-Control", "no-store");
|
reply.header("Cache-Control", "no-store");
|
||||||
return { ...result, strategy: config.updateStrategy };
|
return { ...result, strategy: config.updateStrategy };
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
// A failed upstream request is not a successful check. Release the
|
||||||
|
// reservation only when this request still owns it, so a concurrent
|
||||||
|
// successful check cannot have its cooldown overwritten.
|
||||||
|
if (reservedCheckedAt !== null && rateState.checkedAt === reservedCheckedAt) rateState.checkedAt = previousCheckedAt;
|
||||||
writeAudit(database.sqlite, {
|
writeAudit(database.sqlite, {
|
||||||
requestId: request.id,
|
requestId: request.id,
|
||||||
actorAdminId: request.auth!.admin.id,
|
actorAdminId: request.auth!.admin.id,
|
||||||
@@ -1185,6 +1182,8 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||||
|
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||||
|
download_speed_bps AS downloadSpeedBps,
|
||||||
requested_at AS applyQueuedAt
|
requested_at AS applyQueuedAt
|
||||||
FROM update_jobs WHERE id=? AND admin_id=?
|
FROM update_jobs WHERE id=? AND admin_id=?
|
||||||
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
|
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||||
|
|||||||
+18
-1
@@ -291,7 +291,24 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
|
|||||||
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
|
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
|
||||||
try {
|
try {
|
||||||
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
|
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
|
||||||
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, options);
|
const progressStartedAt = Date.now();
|
||||||
|
let lastProgressWrite = 0;
|
||||||
|
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, {
|
||||||
|
...options,
|
||||||
|
onProgress: (downloadedBytes, totalBytes) => {
|
||||||
|
const now = Date.now();
|
||||||
|
if (!options.sqlite || now - lastProgressWrite < 250) return;
|
||||||
|
lastProgressWrite = now;
|
||||||
|
const elapsed = Math.max(1, now - progressStartedAt);
|
||||||
|
const speedBps = Math.round(downloadedBytes * 1000 / elapsed);
|
||||||
|
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=COALESCE(?, size_bytes), download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloadedBytes, totalBytes, progressStartedAt, speedBps, now, jobId);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
if (options.sqlite) {
|
||||||
|
const finishedAt = Date.now();
|
||||||
|
const elapsed = Math.max(1, finishedAt - progressStartedAt);
|
||||||
|
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=?, download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloaded.size, downloaded.size, progressStartedAt, Math.round(downloaded.size * 1000 / elapsed), finishedAt, jobId);
|
||||||
|
}
|
||||||
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
|
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
|
||||||
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
|
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
|
||||||
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
||||||
|
|||||||
@@ -148,6 +148,9 @@ export const updateJobs = sqliteTable("update_jobs", {
|
|||||||
downloadPath: text("download_path"),
|
downloadPath: text("download_path"),
|
||||||
backupPath: text("backup_path"),
|
backupPath: text("backup_path"),
|
||||||
sizeBytes: integer("size_bytes"),
|
sizeBytes: integer("size_bytes"),
|
||||||
|
downloadedBytes: integer("downloaded_bytes"),
|
||||||
|
downloadStartedAt: integer("download_started_at"),
|
||||||
|
downloadSpeedBps: integer("download_speed_bps"),
|
||||||
errorMessage: text("error_message"),
|
errorMessage: text("error_message"),
|
||||||
createdAt: integer("created_at").notNull(),
|
createdAt: integer("created_at").notNull(),
|
||||||
requestedAt: integer("requested_at"),
|
requestedAt: integer("requested_at"),
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { lstatSync, realpathSync, unlinkSync } from "node:fs";
|
import { lstatSync, realpathSync, readFileSync, unlinkSync } from "node:fs";
|
||||||
import { chmod, mkdir, rename, writeFile } from "node:fs/promises";
|
import { chmod, mkdir, rename, writeFile } from "node:fs/promises";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import { createPublicKey, randomUUID, verify as verifySignature } from "node:crypto";
|
import { createPublicKey, randomUUID, verify as verifySignature } from "node:crypto";
|
||||||
@@ -351,6 +351,9 @@ export function publicUpdateJob(row: Record<string, unknown> | undefined): Recor
|
|||||||
platform: row.platform,
|
platform: row.platform,
|
||||||
assetName: row.assetName ?? null,
|
assetName: row.assetName ?? null,
|
||||||
sizeBytes: row.sizeBytes ?? null,
|
sizeBytes: row.sizeBytes ?? null,
|
||||||
|
downloadedBytes: row.downloadedBytes ?? null,
|
||||||
|
downloadStartedAt: row.downloadStartedAt ?? null,
|
||||||
|
downloadSpeedBps: row.downloadSpeedBps ?? null,
|
||||||
// Do not expose filesystem paths, command output, or upstream response
|
// Do not expose filesystem paths, command output, or upstream response
|
||||||
// text through the authenticated status endpoint. Detailed diagnostics
|
// text through the authenticated status endpoint. Detailed diagnostics
|
||||||
// remain in the server journal for operators.
|
// remain in the server journal for operators.
|
||||||
@@ -385,6 +388,17 @@ function removeExpiredRequest(filePath: string, now: number): void {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function requestJobId(filePath: string): string | null {
|
||||||
|
try {
|
||||||
|
const info = lstatSync(filePath);
|
||||||
|
if (!info.isFile() || info.isSymbolicLink()) return null;
|
||||||
|
const value = JSON.parse(readFileSync(filePath, "utf8")) as { jobId?: unknown };
|
||||||
|
return typeof value.jobId === "string" && /^[0-9a-f-]{36}$/.test(value.jobId) ? value.jobId : null;
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
function currentReleaseVersion(config: AppConfig): string | null {
|
function currentReleaseVersion(config: AppConfig): string | null {
|
||||||
try {
|
try {
|
||||||
const target = realpathSync(config.currentLink);
|
const target = realpathSync(config.currentLink);
|
||||||
@@ -425,6 +439,7 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
|||||||
// row is still safe to retry and must not block the queue forever.
|
// row is still safe to retry and must not block the queue forever.
|
||||||
const releaseVersion = currentReleaseVersion(config);
|
const releaseVersion = currentReleaseVersion(config);
|
||||||
let reconciled = 0;
|
let reconciled = 0;
|
||||||
|
const reconciledIds = new Set<string>();
|
||||||
for (const row of rows) {
|
for (const row of rows) {
|
||||||
if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue;
|
if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue;
|
||||||
// The runner refreshes the state marker while a download is in flight.
|
// The runner refreshes the state marker while a download is in flight.
|
||||||
@@ -451,7 +466,10 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
|||||||
});
|
});
|
||||||
return true;
|
return true;
|
||||||
})();
|
})();
|
||||||
if (changed) reconciled += 1;
|
if (changed) {
|
||||||
|
reconciled += 1;
|
||||||
|
reconciledIds.add(row.id);
|
||||||
|
}
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
if (requestFresh || stateFresh) continue;
|
if (requestFresh || stateFresh) continue;
|
||||||
@@ -476,7 +494,10 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
|||||||
});
|
});
|
||||||
return true;
|
return true;
|
||||||
})();
|
})();
|
||||||
if (changed) reconciled += 1;
|
if (changed) {
|
||||||
|
reconciled += 1;
|
||||||
|
reconciledIds.add(row.id);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
// Prevent a stale request from being replayed after its DB row has been
|
// Prevent a stale request from being replayed after its DB row has been
|
||||||
// marked failed. The path is fixed by the server configuration and the
|
// marked failed. The path is fixed by the server configuration and the
|
||||||
@@ -484,7 +505,17 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
|||||||
// A download runner refreshes the state marker while it is still using the
|
// A download runner refreshes the state marker while it is still using the
|
||||||
// request. Keep the request until that lease also expires; otherwise a
|
// request. Keep the request until that lease also expires; otherwise a
|
||||||
// long download can lose its job id and fail to finalize its row.
|
// long download can lose its job id and fail to finalize its row.
|
||||||
if (!stateFresh && (!requestPresent || (requestMtime !== null && now - requestMtime >= ORPHANED_UPDATE_TIMEOUT_MS))) {
|
const queuedRequestId = requestPresent ? requestJobId(config.updateRequestPath) : null;
|
||||||
|
const queuedRequest = queuedRequestId ? rows.find((row) => row.id === queuedRequestId) : undefined;
|
||||||
|
const requestStillNeeded = Boolean(
|
||||||
|
queuedRequest
|
||||||
|
&& ACTIVE_UPDATE_STATUSES.includes(queuedRequest.status)
|
||||||
|
&& !reconciledIds.has(queuedRequest.id)
|
||||||
|
&& !(queuedRequest.status === "staged" && queuedRequest.operation === "download"),
|
||||||
|
);
|
||||||
|
if (!stateFresh
|
||||||
|
&& (!requestPresent || (requestMtime !== null && now - requestMtime >= ORPHANED_UPDATE_TIMEOUT_MS))
|
||||||
|
&& !requestStillNeeded) {
|
||||||
removeExpiredRequest(config.updateRequestPath, now);
|
removeExpiredRequest(config.updateRequestPath, now);
|
||||||
}
|
}
|
||||||
return reconciled;
|
return reconciled;
|
||||||
|
|||||||
+3
-1
@@ -423,7 +423,7 @@ export async function verifySha256(filePath: string, expected: string): Promise<
|
|||||||
export async function downloadReleaseAsset(
|
export async function downloadReleaseAsset(
|
||||||
url: string | URL,
|
url: string | URL,
|
||||||
destination: string,
|
destination: string,
|
||||||
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined } = {},
|
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined; onProgress?: ((downloadedBytes: number, totalBytes: number | null) => void) | undefined } = {},
|
||||||
): Promise<{ size: number; sha256: string }> {
|
): Promise<{ size: number; sha256: string }> {
|
||||||
const fetchImpl = options.fetchImpl ?? fetch;
|
const fetchImpl = options.fetchImpl ?? fetch;
|
||||||
let current = validateHttpsUrl(url, options);
|
let current = validateHttpsUrl(url, options);
|
||||||
@@ -446,6 +446,7 @@ export async function downloadReleaseAsset(
|
|||||||
}
|
}
|
||||||
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
|
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
|
||||||
const declared = Number(response.headers.get("content-length") ?? 0);
|
const declared = Number(response.headers.get("content-length") ?? 0);
|
||||||
|
const totalBytes = Number.isSafeInteger(declared) && declared > 0 ? declared : null;
|
||||||
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
|
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
|
||||||
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
|
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
|
||||||
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
|
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
|
||||||
@@ -454,6 +455,7 @@ export async function downloadReleaseAsset(
|
|||||||
const hash = createHash("sha256");
|
const hash = createHash("sha256");
|
||||||
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
|
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
|
||||||
size += chunk.length;
|
size += chunk.length;
|
||||||
|
options.onProgress?.(size, totalBytes);
|
||||||
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
|
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
|
||||||
hash.update(chunk);
|
hash.update(chunk);
|
||||||
callback(null, chunk);
|
callback(null, chunk);
|
||||||
|
|||||||
+3
-3
@@ -129,10 +129,10 @@ describe("TallyNote API", () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
it("拒绝没有 Origin 的写请求", async () => {
|
it("反向代理缺少 Origin 时仍允许登录请求进入认证流程", async () => {
|
||||||
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
||||||
expect(response.statusCode).toBe(403);
|
expect(response.statusCode).toBe(401);
|
||||||
expect(response.json().error.code).toBe("ORIGIN_FORBIDDEN");
|
expect(response.json().error.code).toBe("INVALID_CREDENTIALS");
|
||||||
});
|
});
|
||||||
|
|
||||||
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
||||||
|
|||||||
@@ -42,9 +42,10 @@ describe("数据库迁移", () => {
|
|||||||
{ name: "0002_update_jobs.sql" },
|
{ name: "0002_update_jobs.sql" },
|
||||||
{ name: "0003_update_job_ownership.sql" },
|
{ name: "0003_update_job_ownership.sql" },
|
||||||
{ name: "0004_update_download_apply.sql" },
|
{ name: "0004_update_download_apply.sql" },
|
||||||
|
{ name: "0005_update_progress.sql" },
|
||||||
]);
|
]);
|
||||||
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
|
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
|
||||||
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation"]));
|
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation", "downloaded_bytes", "download_started_at", "download_speed_bps"]));
|
||||||
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
|
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
|
||||||
migrated.sqlite.close();
|
migrated.sqlite.close();
|
||||||
migrated = openDatabase(config);
|
migrated = openDatabase(config);
|
||||||
|
|||||||
@@ -48,6 +48,7 @@ describe("部署安全配置", () => {
|
|||||||
expect(loadConfig().trustProxy).toBe(1);
|
expect(loadConfig().trustProxy).toBe(1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
||||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
|
||||||
|
|||||||
@@ -76,6 +76,12 @@ describe("更新 API", () => {
|
|||||||
expect(tooSoon.statusCode).toBe(429);
|
expect(tooSoon.statusCode).toBe(429);
|
||||||
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
||||||
|
|
||||||
|
// Cooldown is scoped to the authenticated administrator, not the whole
|
||||||
|
// database or release endpoint.
|
||||||
|
const otherSession = await login("update-admin-other");
|
||||||
|
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
|
||||||
|
expect(otherChecked.statusCode).toBe(200);
|
||||||
|
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
const jobId = applied.json().job.id as string;
|
const jobId = applied.json().job.id as string;
|
||||||
@@ -157,6 +163,12 @@ describe("更新 API", () => {
|
|||||||
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
||||||
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||||
expect(response.statusCode).toBe(502);
|
expect(response.statusCode).toBe(502);
|
||||||
|
// A failed upstream check must not reserve the per-admin cooldown; an
|
||||||
|
// operator can retry immediately after fixing the release endpoint.
|
||||||
|
const check = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
|
expect(check.statusCode).toBe(502);
|
||||||
|
const retry = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
|
expect(retry.statusCode).toBe(502);
|
||||||
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
||||||
expect(audit?.outcome).toBe("failure");
|
expect(audit?.outcome).toBe("failure");
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -372,6 +372,47 @@ describe("更新安全工具", () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("队列任务有新请求标记时可被重新检查,标记过期后才回收", async () => {
|
||||||
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-queued-marker-"));
|
||||||
|
let database: ReturnType<typeof openDatabase> | undefined;
|
||||||
|
try {
|
||||||
|
const dataDir = path.join(root, "data");
|
||||||
|
const installPrefix = path.join(root, "install");
|
||||||
|
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||||
|
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||||
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||||
|
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||||
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
|
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||||
|
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||||
|
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||||
|
const config = loadConfig();
|
||||||
|
prepareDataDirectories(config);
|
||||||
|
database = openDatabase(config);
|
||||||
|
const staleAt = Date.now() - ORPHANED_UPDATE_TIMEOUT_MS - 1;
|
||||||
|
const jobId = randomUUID();
|
||||||
|
database.sqlite.prepare(`
|
||||||
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
|
VALUES (?, 'apply', 'queued', '1.2.0', 'linux-x64', ?, ?, ?)
|
||||||
|
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||||
|
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
|
||||||
|
const now = Date.now();
|
||||||
|
await utimes(config.updateRequestPath, new Date(now), new Date(now));
|
||||||
|
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "queued" });
|
||||||
|
expect(await stat(config.updateRequestPath)).toBeTruthy();
|
||||||
|
|
||||||
|
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||||
|
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||||
|
} finally {
|
||||||
|
if (database) database.sqlite.close();
|
||||||
|
await rm(root, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
it("流式解包在展开大小上限前拒绝高压缩比归档,并修正发布树权限", async () => {
|
it("流式解包在展开大小上限前拒绝高压缩比归档,并修正发布树权限", async () => {
|
||||||
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-stream-"));
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-stream-"));
|
||||||
try {
|
try {
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ export default function ExpenseDetail({ expense, timezone = "Asia/Shanghai", onC
|
|||||||
</Drawer>
|
</Drawer>
|
||||||
<Dialog visible={action === "status"} header={detail.status === "reimbursed" ? "改回未报销?" : "标记为已报销?"} confirmBtn={{ content: "确认变更", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void updateStatus()} onCancel={() => { if (!busy) setAction(null); }}>{detail.status === "reimbursed" ? "这笔账目会重新出现在未报销列表。" : "确认这笔账目已完成报销,并从未报销列表移出?"}</Dialog>
|
<Dialog visible={action === "status"} header={detail.status === "reimbursed" ? "改回未报销?" : "标记为已报销?"} confirmBtn={{ content: "确认变更", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void updateStatus()} onCancel={() => { if (!busy) setAction(null); }}>{detail.status === "reimbursed" ? "这笔账目会重新出现在未报销列表。" : "确认这笔账目已完成报销,并从未报销列表移出?"}</Dialog>
|
||||||
<Dialog visible={action === "trash"} header="移入回收站?" confirmBtn={{ content: "移入回收站", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void trash()} onCancel={() => { if (!busy) setAction(null); }}>账目会从普通列表和导出结果中隐藏,附件会保留,可在回收站恢复。</Dialog>
|
<Dialog visible={action === "trash"} header="移入回收站?" confirmBtn={{ content: "移入回收站", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void trash()} onCancel={() => { if (!busy) setAction(null); }}>账目会从普通列表和导出结果中隐藏,附件会保留,可在回收站恢复。</Dialog>
|
||||||
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert"><AlertCircle size={16} />{removeError}</div>}</>}</Dialog>
|
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert">{removeError}</div>}</>}</Dialog>
|
||||||
<Dialog visible={Boolean(preview)} header={preview?.originalName} onClose={() => setPreview(null)} cancelBtn="关闭" footer={null}>{preview && <div className="tn-preview">{preview.mimeType.startsWith("image/") ? <img src={`/api/attachments/${preview.id}/content`} alt={preview.originalName} /> : <iframe src={`/api/attachments/${preview.id}/content`} title={preview.originalName} />}</div>}</Dialog>
|
<Dialog visible={Boolean(preview)} header={preview?.originalName} onClose={() => setPreview(null)} cancelBtn="关闭" footer={null}>{preview && <div className="tn-preview">{preview.mimeType.startsWith("image/") ? <img src={`/api/attachments/${preview.id}/content`} alt={preview.originalName} /> : <iframe src={`/api/attachments/${preview.id}/content`} title={preview.originalName} />}</div>}</Dialog>
|
||||||
</>;
|
</>;
|
||||||
}
|
}
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,283 @@
|
|||||||
|
export type MockScenario =
|
||||||
|
| "latest" // 已是最新
|
||||||
|
| "available" // 发现新版本(待下载)
|
||||||
|
| "downloading_30" // 下载中 30%
|
||||||
|
| "downloading_85" // 下载中 85% + 高速
|
||||||
|
| "staged" // 下载完成已校验,待立即更新
|
||||||
|
| "backing_up" // 正在备份数据
|
||||||
|
| "applying" // 正在原子切换并重启中(倒计时)
|
||||||
|
| "completed" // 更新完成
|
||||||
|
| "failed_verify" // 完整性校验失败
|
||||||
|
| "disabled"; // 手动模式未配置源
|
||||||
|
|
||||||
|
export interface MockUpdateState {
|
||||||
|
info: any;
|
||||||
|
title: string;
|
||||||
|
description: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export const MOCK_SCENARIOS: Record<MockScenario, MockUpdateState> = {
|
||||||
|
latest: {
|
||||||
|
title: "版本健康(已是最新)",
|
||||||
|
description: "展示当前运行版本已是最新,各项指标正常,无待处理任务",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 600_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.22",
|
||||||
|
tagName: "v1.1.22",
|
||||||
|
releaseName: "v1.1.22 稳定版",
|
||||||
|
publishedAt: new Date(Date.now() - 3600_000 * 24).toISOString(),
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: true,
|
||||||
|
signatureReady: true,
|
||||||
|
isNewer: false,
|
||||||
|
assetName: "tallynote-1.1.22-linux-x64-glibc.tar.gz",
|
||||||
|
assetSize: 120540160,
|
||||||
|
notes: "### TallyNote 1.1.22\n\n- 优化反向代理下登录兼容性\n- 增强安全审计与防重放机制\n- 前端组件性能深度优化",
|
||||||
|
},
|
||||||
|
job: null,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
available: {
|
||||||
|
title: "发现新版本(待下载)",
|
||||||
|
description: "检查到官方发布了更高版本,显示更新日志与文件校验信息,可点击下载",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 60_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.23",
|
||||||
|
tagName: "v1.1.23",
|
||||||
|
releaseName: "v1.1.23 重大更新",
|
||||||
|
publishedAt: new Date(Date.now() - 1800_000).toISOString(),
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: true,
|
||||||
|
signatureReady: true,
|
||||||
|
isNewer: true,
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
assetSize: 121000000,
|
||||||
|
notes: "### TallyNote 1.1.23\n\n- 【新功能】系统更新中心全面重构,支持动态速率流光进度条与平滑重启倒计时\n- 【交互】优化抽屉展开动效与手机端自适应导航\n- 【安全】发布包支持双重 Ed25519 签名与 SHA-256 清单交叉校验",
|
||||||
|
},
|
||||||
|
job: null,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
downloading_30: {
|
||||||
|
title: "下载更新中(进度 38%)",
|
||||||
|
description: "展示真实下载速率、已下载字节数与动态流光进度条",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.23",
|
||||||
|
tagName: "v1.1.23",
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: true,
|
||||||
|
signatureReady: true,
|
||||||
|
isNewer: true,
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
assetSize: 121000000,
|
||||||
|
},
|
||||||
|
job: {
|
||||||
|
id: "mock-job-001",
|
||||||
|
operation: "download",
|
||||||
|
status: "downloading",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
sizeBytes: 121000000,
|
||||||
|
downloadedBytes: 46200000,
|
||||||
|
downloadStartedAt: Date.now() - 10000,
|
||||||
|
downloadSpeedBps: 8800000, // 8.4 MB/s
|
||||||
|
createdAt: Date.now() - 10000,
|
||||||
|
updatedAt: Date.now(),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
downloading_85: {
|
||||||
|
title: "下载冲刺中(进度 88%)",
|
||||||
|
description: "高速冲刺状态,即将触发 SHA-256 校验",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.23",
|
||||||
|
tagName: "v1.1.23",
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: true,
|
||||||
|
signatureReady: true,
|
||||||
|
isNewer: true,
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
assetSize: 121000000,
|
||||||
|
},
|
||||||
|
job: {
|
||||||
|
id: "mock-job-002",
|
||||||
|
operation: "download",
|
||||||
|
status: "downloading",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
sizeBytes: 121000000,
|
||||||
|
downloadedBytes: 106480000,
|
||||||
|
downloadStartedAt: Date.now() - 15000,
|
||||||
|
downloadSpeedBps: 12500000, // 11.9 MB/s
|
||||||
|
createdAt: Date.now() - 15000,
|
||||||
|
updatedAt: Date.now(),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
staged: {
|
||||||
|
title: "下载完成(待立即应用)",
|
||||||
|
description: "更新包与签名均已校验就绪,随时可以安全点击【立即更新】",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.23",
|
||||||
|
tagName: "v1.1.23",
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: true,
|
||||||
|
signatureReady: true,
|
||||||
|
isNewer: true,
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
assetSize: 121000000,
|
||||||
|
notes: "### TallyNote 1.1.23\n\n- 更新包已完整解压检验通过,具备升级条件。",
|
||||||
|
},
|
||||||
|
job: {
|
||||||
|
id: "mock-job-003",
|
||||||
|
operation: "download",
|
||||||
|
status: "staged",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||||
|
sizeBytes: 121000000,
|
||||||
|
downloadedBytes: 121000000,
|
||||||
|
createdAt: Date.now() - 60000,
|
||||||
|
updatedAt: Date.now() - 5000,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
backing_up: {
|
||||||
|
title: "数据备份中(更新保护)",
|
||||||
|
description: "正在为 /var/lib/tallynote 生成自动还原快照",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||||
|
job: {
|
||||||
|
id: "mock-job-004",
|
||||||
|
operation: "apply",
|
||||||
|
status: "backing_up",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
createdAt: Date.now() - 20000,
|
||||||
|
updatedAt: Date.now() - 2000,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
applying: {
|
||||||
|
title: "服务平滑重启中(倒计时中)",
|
||||||
|
description: "已原子切换版本,systemd 正在热重启,前端实时探活",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||||
|
job: {
|
||||||
|
id: "mock-job-005",
|
||||||
|
operation: "apply",
|
||||||
|
status: "applying",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
applyQueuedAt: Date.now() - 12000,
|
||||||
|
restartWindowSeconds: 30,
|
||||||
|
restartDeadline: Date.now() + 18000,
|
||||||
|
createdAt: Date.now() - 25000,
|
||||||
|
updatedAt: Date.now() - 2000,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
completed: {
|
||||||
|
title: "更新成功完成",
|
||||||
|
description: "新版本健康检查通过,已平滑无感升级至最新",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.23",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 30_000,
|
||||||
|
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: false },
|
||||||
|
job: {
|
||||||
|
id: "mock-job-006",
|
||||||
|
operation: "apply",
|
||||||
|
status: "completed",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
completedAt: Date.now() - 10000,
|
||||||
|
createdAt: Date.now() - 45000,
|
||||||
|
updatedAt: Date.now() - 10000,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
failed_verify: {
|
||||||
|
title: "更新失败状态(安全拦截)",
|
||||||
|
description: "模拟签名不匹配或发布包篡改时的安全拦截展示与错误提示",
|
||||||
|
info: {
|
||||||
|
configured: true,
|
||||||
|
strategy: "systemd",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||||
|
checkedAt: Date.now() - 120_000,
|
||||||
|
latest: {
|
||||||
|
version: "1.1.23",
|
||||||
|
tagName: "v1.1.23",
|
||||||
|
compatible: true,
|
||||||
|
integrityReady: false,
|
||||||
|
signatureReady: false,
|
||||||
|
isNewer: true,
|
||||||
|
},
|
||||||
|
job: {
|
||||||
|
id: "mock-job-007",
|
||||||
|
operation: "download",
|
||||||
|
status: "failed",
|
||||||
|
version: "1.1.23",
|
||||||
|
platform: "x64/glibc",
|
||||||
|
errorMessage: "发布包 SHA-256 校验与清单不一致,系统已自动阻断并保护原有数据。",
|
||||||
|
createdAt: Date.now() - 30000,
|
||||||
|
updatedAt: Date.now() - 5000,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
disabled: {
|
||||||
|
title: "手动源码模式",
|
||||||
|
description: "未接入 systemd 时的只读说明与命令引导展示",
|
||||||
|
info: {
|
||||||
|
configured: false,
|
||||||
|
strategy: "disabled",
|
||||||
|
currentVersion: "1.1.22",
|
||||||
|
platform: { target: "macOS/darwin", os: "darwin", arch: "arm64" },
|
||||||
|
checkedAt: Date.now() - 3600_000,
|
||||||
|
latest: null,
|
||||||
|
job: null,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
@@ -410,6 +410,34 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
|||||||
@keyframes tn-app-enter { from { opacity: 0; } to { opacity: 1; } }
|
@keyframes tn-app-enter { from { opacity: 0; } to { opacity: 1; } }
|
||||||
@keyframes tn-auth-page-in { from { opacity: 0; transform: translateY(4px); } to { opacity: 1; transform: translateY(0); } }
|
@keyframes tn-auth-page-in { from { opacity: 0; transform: translateY(4px); } to { opacity: 1; transform: translateY(0); } }
|
||||||
.t-dialog { border: 1px solid var(--tn-border); border-radius: 4px; box-shadow: 0 18px 42px rgba(8, 47, 118, .18); }
|
.t-dialog { border: 1px solid var(--tn-border); border-radius: 4px; box-shadow: 0 18px 42px rgba(8, 47, 118, .18); }
|
||||||
|
/* TDesign Dialog global no-icon & pure baseline typography normalization */
|
||||||
|
.t-dialog__header .t-icon:not(.t-icon-close),
|
||||||
|
.t-dialog__body .t-icon,
|
||||||
|
.t-dialog .t-icon.t-is-info,
|
||||||
|
.t-dialog .t-icon.t-is-success,
|
||||||
|
.t-dialog .t-icon.t-is-warning,
|
||||||
|
.t-dialog .t-icon.t-is-error {
|
||||||
|
display: none !important;
|
||||||
|
}
|
||||||
|
.t-dialog__header {
|
||||||
|
font-size: 16px;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
line-height: 1.4;
|
||||||
|
margin-bottom: 8px;
|
||||||
|
gap: 0 !important;
|
||||||
|
}
|
||||||
|
.t-dialog__header-content {
|
||||||
|
display: block !important;
|
||||||
|
width: 100%;
|
||||||
|
}
|
||||||
|
.t-dialog__body {
|
||||||
|
font-size: 13.5px;
|
||||||
|
line-height: 1.65;
|
||||||
|
color: var(--tn-text);
|
||||||
|
padding: 8px 0 20px 0;
|
||||||
|
}
|
||||||
|
|
||||||
.t-dialog__mask { background: var(--td-mask-active) !important; }
|
.t-dialog__mask { background: var(--td-mask-active) !important; }
|
||||||
.t-dialog__footer .t-button { min-width: 76px; }
|
.t-dialog__footer .t-button { min-width: 76px; }
|
||||||
@media (max-width: 900px) {
|
@media (max-width: 900px) {
|
||||||
@@ -537,3 +565,527 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
|||||||
@media (prefers-reduced-motion: reduce) {
|
@media (prefers-reduced-motion: reduce) {
|
||||||
*, *::before, *::after { animation-duration: .01ms !important; animation-iteration-count: 1 !important; transition-duration: .01ms !important; scroll-behavior: auto !important; }
|
*, *::before, *::after { animation-duration: .01ms !important; animation-iteration-count: 1 !important; transition-duration: .01ms !important; scroll-behavior: auto !important; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* ==========================================================================
|
||||||
|
TallyNote Update Center (Redesigned UI & Interactive Styles)
|
||||||
|
========================================================================== */
|
||||||
|
|
||||||
|
/* Mock Console Controller */
|
||||||
|
.tn-mock-console {
|
||||||
|
margin-bottom: 16px;
|
||||||
|
padding: 14px 18px;
|
||||||
|
background: #f8fbff;
|
||||||
|
border: 1px dashed var(--td-brand-color-3);
|
||||||
|
border-radius: 4px;
|
||||||
|
}
|
||||||
|
.tn-mock-console-header {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: space-between;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
gap: 8px;
|
||||||
|
margin-bottom: 12px;
|
||||||
|
}
|
||||||
|
.tn-mock-console-title {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
font-size: 13px;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
}
|
||||||
|
.tn-mock-console-tip {
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
}
|
||||||
|
.tn-mock-scenario-chips {
|
||||||
|
display: flex;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
gap: 8px;
|
||||||
|
}
|
||||||
|
.tn-scenario-chip {
|
||||||
|
padding: 5px 11px;
|
||||||
|
font-size: 12px;
|
||||||
|
border: 1px solid var(--tn-border);
|
||||||
|
border-radius: 3px;
|
||||||
|
background: #ffffff;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
cursor: pointer;
|
||||||
|
transition: all 0.16s ease;
|
||||||
|
}
|
||||||
|
.tn-scenario-chip:hover {
|
||||||
|
border-color: var(--td-brand-color-4);
|
||||||
|
color: var(--td-brand-color);
|
||||||
|
background: var(--td-brand-color-1);
|
||||||
|
}
|
||||||
|
.tn-scenario-chip.active {
|
||||||
|
background: var(--td-brand-color);
|
||||||
|
border-color: var(--td-brand-color);
|
||||||
|
color: #ffffff;
|
||||||
|
font-weight: 600;
|
||||||
|
box-shadow: 0 2px 6px rgba(23, 92, 211, 0.2);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Update Page Actions */
|
||||||
|
.tn-update-page-actions {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* 4 Metrics Grid */
|
||||||
|
.tn-update-metrics-grid {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: repeat(4, minmax(0, 1fr));
|
||||||
|
gap: 14px;
|
||||||
|
margin-bottom: 16px;
|
||||||
|
}
|
||||||
|
.tn-metric-card .t-card__body {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
justify-content: space-between;
|
||||||
|
padding: 16px 18px;
|
||||||
|
min-height: 104px;
|
||||||
|
}
|
||||||
|
.tn-metric-content {
|
||||||
|
width: 100%;
|
||||||
|
}
|
||||||
|
.tn-metric-label {
|
||||||
|
display: block;
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
margin-bottom: 4px;
|
||||||
|
}
|
||||||
|
.tn-metric-value {
|
||||||
|
font-size: 20px;
|
||||||
|
font-weight: 700;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
line-height: 1.2;
|
||||||
|
}
|
||||||
|
.tn-metric-foot {
|
||||||
|
margin-top: 6px;
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-muted);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Stepper Surface */
|
||||||
|
.tn-stepper-surface {
|
||||||
|
margin-bottom: 16px;
|
||||||
|
padding: 20px;
|
||||||
|
}
|
||||||
|
.tn-stepper-head {
|
||||||
|
display: flex;
|
||||||
|
align-items: flex-start;
|
||||||
|
justify-content: space-between;
|
||||||
|
gap: 16px;
|
||||||
|
margin-bottom: 20px;
|
||||||
|
}
|
||||||
|
.tn-section-heading {
|
||||||
|
margin: 0 0 4px;
|
||||||
|
font-size: 15px;
|
||||||
|
font-weight: 700;
|
||||||
|
color: var(--tn-text);
|
||||||
|
}
|
||||||
|
.tn-section-subheading {
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap {
|
||||||
|
padding: 10px 0 20px;
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap .t-steps {
|
||||||
|
max-width: 860px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap {
|
||||||
|
min-width: 0;
|
||||||
|
overflow-x: auto;
|
||||||
|
scrollbar-width: thin;
|
||||||
|
scrollbar-color: var(--td-brand-color-3) transparent;
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap .t-steps {
|
||||||
|
min-width: 680px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Job Runtime Panel (Active download & progress) */
|
||||||
|
.tn-job-runtime-panel {
|
||||||
|
margin-top: 14px;
|
||||||
|
padding: 16px;
|
||||||
|
background: #f8fbff;
|
||||||
|
border: 1px solid var(--td-brand-color-2);
|
||||||
|
border-radius: 4px;
|
||||||
|
}
|
||||||
|
.tn-job-runtime-header {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: space-between;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
gap: 10px;
|
||||||
|
margin-bottom: 12px;
|
||||||
|
}
|
||||||
|
.tn-job-status-badge {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
font-size: 13px;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
min-width: 0;
|
||||||
|
overflow-wrap: anywhere;
|
||||||
|
}
|
||||||
|
.tn-pulse-dot {
|
||||||
|
width: 8px;
|
||||||
|
height: 8px;
|
||||||
|
border-radius: 50%;
|
||||||
|
background: var(--td-brand-color);
|
||||||
|
box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7);
|
||||||
|
animation: tn-pulse 1.8s infinite;
|
||||||
|
}
|
||||||
|
@keyframes tn-pulse {
|
||||||
|
0% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7); }
|
||||||
|
70% { transform: scale(1); box-shadow: 0 0 0 6px rgba(23, 92, 211, 0); }
|
||||||
|
100% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0); }
|
||||||
|
}
|
||||||
|
.tn-job-subtext {
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
font-size: 12px;
|
||||||
|
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
}
|
||||||
|
.tn-speed-indicator {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
min-width: 0;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
}
|
||||||
|
.tn-speed-badge {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 4px;
|
||||||
|
padding: 2px 8px;
|
||||||
|
border-radius: 3px;
|
||||||
|
background: #ffffff;
|
||||||
|
border: 1px solid var(--td-brand-color-3);
|
||||||
|
color: var(--td-brand-color);
|
||||||
|
font-size: 12px;
|
||||||
|
font-weight: 600;
|
||||||
|
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
}
|
||||||
|
.tn-eta-badge {
|
||||||
|
display: inline-block;
|
||||||
|
padding: 2px 8px;
|
||||||
|
border-radius: 3px;
|
||||||
|
background: #f2f5f9;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
font-size: 12px;
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Progress Bar with modern stream light effect */
|
||||||
|
.tn-progress-stream {
|
||||||
|
position: relative;
|
||||||
|
height: 8px;
|
||||||
|
background: #e1e9f4;
|
||||||
|
border-radius: 999px;
|
||||||
|
overflow: hidden;
|
||||||
|
margin-bottom: 12px;
|
||||||
|
}
|
||||||
|
.tn-progress-stream-bar {
|
||||||
|
height: 100%;
|
||||||
|
background: linear-gradient(90deg, #175cd3 0%, #3d7be5 100%);
|
||||||
|
border-radius: inherit;
|
||||||
|
transition: width 0.35s ease;
|
||||||
|
position: relative;
|
||||||
|
}
|
||||||
|
.tn-progress-stream-bar::after {
|
||||||
|
content: "";
|
||||||
|
position: absolute;
|
||||||
|
top: 0; left: 0; bottom: 0; right: 0;
|
||||||
|
background-image: linear-gradient(
|
||||||
|
-45deg,
|
||||||
|
rgba(255, 255, 255, 0.25) 25%,
|
||||||
|
transparent 25%,
|
||||||
|
transparent 50%,
|
||||||
|
rgba(255, 255, 255, 0.25) 50%,
|
||||||
|
rgba(255, 255, 255, 0.25) 75%,
|
||||||
|
transparent 75%,
|
||||||
|
transparent
|
||||||
|
);
|
||||||
|
background-size: 30px 30px;
|
||||||
|
animation: tn-stream-flow 1.5s linear infinite;
|
||||||
|
}
|
||||||
|
@keyframes tn-stream-flow {
|
||||||
|
0% { background-position: 0 0; }
|
||||||
|
100% { background-position: 30px 30px; }
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-job-runtime-desc {
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
line-height: 1.6;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Restarting State Banner */
|
||||||
|
.tn-restarting-banner {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 12px;
|
||||||
|
padding: 8px 12px;
|
||||||
|
background: #fff8e6;
|
||||||
|
border: 1px solid #ffd666;
|
||||||
|
border-radius: 3px;
|
||||||
|
color: #8c5b00;
|
||||||
|
}
|
||||||
|
.tn-restarting-spinner {
|
||||||
|
color: #faad14;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Release Surface */
|
||||||
|
.tn-release-surface {
|
||||||
|
margin-bottom: 16px;
|
||||||
|
padding: 20px;
|
||||||
|
}
|
||||||
|
.tn-release-header {
|
||||||
|
display: flex;
|
||||||
|
align-items: flex-start;
|
||||||
|
justify-content: space-between;
|
||||||
|
gap: 16px;
|
||||||
|
}
|
||||||
|
.tn-release-tag-row {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
margin-bottom: 6px;
|
||||||
|
}
|
||||||
|
.tn-release-title {
|
||||||
|
margin: 0 0 6px;
|
||||||
|
font-size: 22px;
|
||||||
|
font-weight: 700;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
}
|
||||||
|
.tn-release-time {
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
}
|
||||||
|
.tn-release-notes-box {
|
||||||
|
margin: 16px 0;
|
||||||
|
padding: 12px 16px;
|
||||||
|
background: #f8fafc;
|
||||||
|
border: 1px solid var(--tn-border);
|
||||||
|
border-left: 3px solid var(--td-brand-color);
|
||||||
|
border-radius: 3px;
|
||||||
|
}
|
||||||
|
.tn-release-notes-heading {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 6px;
|
||||||
|
font-size: 12px;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
margin-bottom: 6px;
|
||||||
|
}
|
||||||
|
.tn-release-notes-content {
|
||||||
|
font-size: 13px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
line-height: 1.6;
|
||||||
|
max-height: 140px;
|
||||||
|
overflow-y: auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-markdown-notes {
|
||||||
|
color: inherit;
|
||||||
|
line-height: 1.7;
|
||||||
|
overflow-wrap: anywhere;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes p,
|
||||||
|
.tn-markdown-notes h3,
|
||||||
|
.tn-markdown-notes h4,
|
||||||
|
.tn-markdown-notes h5 {
|
||||||
|
margin: 0 0 8px;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes p:last-child,
|
||||||
|
.tn-markdown-notes ul:last-child,
|
||||||
|
.tn-markdown-notes pre:last-child,
|
||||||
|
.tn-markdown-notes h3:last-child,
|
||||||
|
.tn-markdown-notes h4:last-child,
|
||||||
|
.tn-markdown-notes h5:last-child {
|
||||||
|
margin-bottom: 0;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes h3,
|
||||||
|
.tn-markdown-notes h4,
|
||||||
|
.tn-markdown-notes h5 {
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
font-weight: 700;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes h3 { font-size: 15px; }
|
||||||
|
.tn-markdown-notes h4 { font-size: 14px; }
|
||||||
|
.tn-markdown-notes h5 { font-size: 13px; }
|
||||||
|
.tn-markdown-notes ul {
|
||||||
|
margin: 0 0 8px;
|
||||||
|
padding-left: 20px;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes li { margin: 3px 0; }
|
||||||
|
.tn-markdown-notes strong { color: var(--tn-navy-900); font-weight: 700; }
|
||||||
|
.tn-markdown-notes code {
|
||||||
|
padding: 1px 4px;
|
||||||
|
border: 1px solid var(--tn-border-subtle);
|
||||||
|
border-radius: 3px;
|
||||||
|
background: #f2f5f9;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
font-family: "Plus Jakarta Sans Variable", ui-monospace, monospace;
|
||||||
|
font-size: .92em;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes pre {
|
||||||
|
margin: 0 0 8px;
|
||||||
|
padding: 10px 12px;
|
||||||
|
overflow-x: auto;
|
||||||
|
border: 1px solid var(--tn-border-subtle);
|
||||||
|
border-radius: 3px;
|
||||||
|
background: #f8fafc;
|
||||||
|
white-space: pre-wrap;
|
||||||
|
}
|
||||||
|
.tn-markdown-notes pre code { padding: 0; border: 0; background: transparent; }
|
||||||
|
.tn-markdown-notes a { color: var(--td-brand-color); text-decoration: underline; text-underline-offset: 2px; }
|
||||||
|
.tn-markdown-notes-compact { font-size: 13px; }
|
||||||
|
|
||||||
|
/* Facts Grid */
|
||||||
|
.tn-facts-grid {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: repeat(3, minmax(0, 1fr));
|
||||||
|
gap: 14px;
|
||||||
|
margin: 18px 0;
|
||||||
|
padding: 14px 0;
|
||||||
|
border-top: 1px solid var(--tn-border-subtle);
|
||||||
|
border-bottom: 1px solid var(--tn-border-subtle);
|
||||||
|
}
|
||||||
|
.tn-fact-item {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
gap: 4px;
|
||||||
|
}
|
||||||
|
.tn-fact-label {
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
}
|
||||||
|
.tn-fact-value {
|
||||||
|
font-size: 14px;
|
||||||
|
color: var(--tn-text);
|
||||||
|
font-weight: 600;
|
||||||
|
overflow-wrap: anywhere;
|
||||||
|
}
|
||||||
|
.tn-fact-hint {
|
||||||
|
font-size: 11px;
|
||||||
|
color: var(--tn-text-muted);
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-release-card-actions {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 12px;
|
||||||
|
margin-top: 16px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Dialog content styles */
|
||||||
|
.tn-confirm-dialog-content {
|
||||||
|
font-size: 13px;
|
||||||
|
line-height: 1.6;
|
||||||
|
color: var(--tn-text);
|
||||||
|
}
|
||||||
|
.tn-update-safety-tips {
|
||||||
|
margin-top: 10px;
|
||||||
|
padding: 10px 14px;
|
||||||
|
background: #f6f8fb;
|
||||||
|
border-radius: 3px;
|
||||||
|
border: 1px solid var(--tn-border-subtle);
|
||||||
|
font-size: 12px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
gap: 4px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-full-notes-modal {
|
||||||
|
margin: 0;
|
||||||
|
padding: 12px;
|
||||||
|
background: #f8fafc;
|
||||||
|
border-radius: 3px;
|
||||||
|
font-size: 13px;
|
||||||
|
line-height: 1.6;
|
||||||
|
color: var(--tn-text);
|
||||||
|
max-height: 50vh;
|
||||||
|
overflow-y: auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-empty-surface {
|
||||||
|
padding: 36px 20px;
|
||||||
|
text-align: center;
|
||||||
|
}
|
||||||
|
.tn-empty-content {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
color: var(--tn-text-secondary);
|
||||||
|
font-size: 13px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.tn-inline-warning {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
padding: 10px 14px;
|
||||||
|
margin-bottom: 14px;
|
||||||
|
background: #fffbe6;
|
||||||
|
border: 1px solid #ffe58f;
|
||||||
|
border-radius: 3px;
|
||||||
|
color: #d48806;
|
||||||
|
font-size: 13px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Responsive adjustments */
|
||||||
|
@media (max-width: 992px) {
|
||||||
|
.tn-update-metrics-grid {
|
||||||
|
grid-template-columns: repeat(2, minmax(0, 1fr));
|
||||||
|
}
|
||||||
|
.tn-facts-grid {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
@media (max-width: 640px) {
|
||||||
|
.tn-update-metrics-grid {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
}
|
||||||
|
.tn-mock-console-header {
|
||||||
|
flex-direction: column;
|
||||||
|
align-items: flex-start;
|
||||||
|
}
|
||||||
|
.tn-release-header {
|
||||||
|
flex-direction: column;
|
||||||
|
}
|
||||||
|
.tn-release-card-actions {
|
||||||
|
flex-direction: column;
|
||||||
|
width: 100%;
|
||||||
|
}
|
||||||
|
.tn-release-card-actions .t-button {
|
||||||
|
width: 100%;
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap {
|
||||||
|
margin-inline: -4px;
|
||||||
|
padding-inline: 4px;
|
||||||
|
}
|
||||||
|
.tn-stepper-wrap .t-steps {
|
||||||
|
min-width: 620px;
|
||||||
|
}
|
||||||
|
.tn-job-runtime-header {
|
||||||
|
align-items: stretch;
|
||||||
|
}
|
||||||
|
.tn-job-status-badge,
|
||||||
|
.tn-speed-indicator {
|
||||||
|
width: 100%;
|
||||||
|
}
|
||||||
|
.tn-speed-indicator {
|
||||||
|
justify-content: flex-start;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+1
-1
@@ -771,7 +771,7 @@ function Update({ notify }: { notify: (message: string, kind?: Notice["kind"]) =
|
|||||||
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && (!job || job.status === "failed" || job.version !== latest.version));
|
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && (!job || job.status === "failed" || job.version !== latest.version));
|
||||||
|
|
||||||
return <div className="page update-page">
|
return <div className="page update-page">
|
||||||
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking || hasActiveJob}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
||||||
{error && <div className="error banner" role="alert"><AlertCircle size={16} />{error}<button className="text-button" onClick={() => void load()}>重试</button></div>}
|
{error && <div className="error banner" role="alert"><AlertCircle size={16} />{error}<button className="text-button" onClick={() => void load()}>重试</button></div>}
|
||||||
{loading ? <div className="update-loading"><Loader2 className="spin" size={22} />正在读取版本信息</div> : info && <>
|
{loading ? <div className="update-loading"><Loader2 className="spin" size={22} />正在读取版本信息</div> : info && <>
|
||||||
<div className="update-overview">
|
<div className="update-overview">
|
||||||
|
|||||||
Reference in New Issue
Block a user