fix: 开启自助注册须先有 8-64 字符安全码

This commit is contained in:
Nixevol
2026-09-30 16:21:51 +08:00
parent 659373e142
commit 8c20b76df5
9 changed files with 230 additions and 8 deletions
+8
View File
@@ -25,6 +25,9 @@ const (
settingRegistrationEnabled = "registration_enabled"
settingRegistrationCode = "registration_code"
minRegistrationCodeLen = 8
maxRegistrationCodeLen = 64
sourceSelf = "self"
idAlphabet = "abcdefghijklmnopqrstuvwxyz0123456789"
@@ -144,6 +147,11 @@ func (h *RegisterHandler) register(ctx context.Context, req *protocol.RegisterRe
if !enabled {
return RegisterResult{}, apiErr(http.StatusForbidden, protocol.CodeRegistrationClosed, "registration closed")
}
// 存储码不是 8–64 字符时视为关闭(含开启+空码的旧库)。放在锁定检查之前,不计入锁定。
if n := utf8.RuneCountInString(storedCode); n < minRegistrationCodeLen || n > maxRegistrationCodeLen {
h.cfg.Logger.Warn("register", "result", protocol.CodeRegistrationClosed, "reason", "unusable_code", "ip", ip)
return RegisterResult{}, apiErr(http.StatusForbidden, protocol.CodeRegistrationClosed, "registration closed")
}
lockKey := auth.LockKey{Kind: auth.LockRegisterIP, IP: ip}
if locked, _ := h.cfg.Locks.Check(lockKey); locked {