feat: 登录设备管理与编辑器图片上传

- 新增登录设备列表与会话下线(ListLoginDevices/RevokeLoginDevice),按设备指纹识别当前会话
- Markdown 编辑器新增图片插入弹窗与图片上传(ImageInsertModal)
- 实时总线、账号守卫与用户事件适配
This commit is contained in:
2026-09-26 01:10:10 +08:00
parent 5270fee2b7
commit 31f5360c26
12 changed files with 706 additions and 165 deletions

View File

@@ -32,12 +32,14 @@ export function onUserUpdate(handler: (patch: Partial<User>) => void): () => voi
* 强制下线事件。
*
* 触发源统一收敛在 lib/api.ts:任何客户端请求收到后端的
* code=account_banned(中间件/refresh/登录)或 /me 的 banned 标记时派发,
* Header 负责复用登出清理链路(清 cookie、游客化、router.refresh),
* AccountGuard 负责弹出封禁告知——状态清理与告知 UI 解耦,
* 避免各请求调用方各自处理导致残留(参考强制下线单一入口原则)。
* code=account_banned(中间件/refresh/登录)或 /me 的 banned 标记时派发;
* 登录态被顶/被剔除(其他浏览器登录、安全设置剔除设备)经探测确认后
* 以 reason=session_replaced 派发。Header 负责复用登出清理链路
* (清 cookie、游客化、router.refresh),AccountGuard 负责弹出对应告知——
* 状态清理与告知 UI 解耦,避免各请求调用方各自处理导致残留
* (参考强制下线单一入口原则)。
*/
export type ForceLogoutReason = "banned";
export type ForceLogoutReason = "banned" | "session_replaced";
export const FORCE_LOGOUT_EVENT = "j13:force-logout";