feat: 安全设置展示有效登录会话,支持剔除其它设备
按设备指纹去重并直出 IP;非当前会话可踢下线,对方需重新输入密码。 Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -1,16 +1,20 @@
|
||||
import Link from "next/link";
|
||||
import { cookies } from "next/headers";
|
||||
import { cookies, headers } from "next/headers";
|
||||
import { Metadata } from "next";
|
||||
import {
|
||||
ChevronRight, FileText, MessageCircle, Flame, Calendar, Hash, Shield,
|
||||
Settings, KeyRound, Info, PenLine,
|
||||
} from "lucide-react";
|
||||
import { fetchUserProfile, fetchUserComments, type UserProfile, type UserCommentsResponse } from "@/lib/api";
|
||||
import { authCookieHeader } from "@/lib/cookies";
|
||||
import {
|
||||
fetchUserProfile, fetchUserComments, fetchLoginDevices,
|
||||
type UserProfile, type UserCommentsResponse, type LoginDevice,
|
||||
} from "@/lib/api";
|
||||
import { authCookieHeader, sessionCookieHeader } from "@/lib/cookies";
|
||||
import { getMeCached, getPublicSettingsCached } from "@/lib/serverData";
|
||||
import UserProfileContent from "./UserProfileContent";
|
||||
import ProfileForm from "./ProfileForm";
|
||||
import PasswordForm from "./PasswordForm";
|
||||
import LoginDevices from "./LoginDevices";
|
||||
import ProfileHeroAvatar from "./ProfileHeroAvatar";
|
||||
import RoleBadge from "@/components/RoleBadge";
|
||||
import { roleMeta } from "@/lib/roles";
|
||||
@@ -96,6 +100,24 @@ export default async function UserPage({ params, searchParams }: UserPageProps)
|
||||
}
|
||||
}
|
||||
|
||||
// 安全设置:仍有效的登录会话(仅本人)
|
||||
// SSR 直连后端时必须转发 refresh cookie + 浏览器 UA/IP,才能标「当前在线」并避免把 Node fetch 当成一台设备
|
||||
let loginDevices: LoginDevice[] = [];
|
||||
if (effectiveTab === "security" && isOwner) {
|
||||
try {
|
||||
const hdrs = await headers();
|
||||
const sessionCookie = sessionCookieHeader(await cookies());
|
||||
loginDevices = await fetchLoginDevices(sessionCookie || cookie || undefined, {
|
||||
userAgent: hdrs.get("user-agent") || undefined,
|
||||
clientIP: hdrs.get("x-forwarded-for")?.split(",")[0]?.trim()
|
||||
|| hdrs.get("x-real-ip")
|
||||
|| undefined,
|
||||
});
|
||||
} catch {
|
||||
loginDevices = [];
|
||||
}
|
||||
}
|
||||
|
||||
const u = data.user;
|
||||
const joinDate = new Date(u.created_at).toLocaleDateString("zh-CN");
|
||||
const showPoints = data.stats.points > 0 || isOwner;
|
||||
@@ -336,6 +358,7 @@ export default async function UserPage({ params, searchParams }: UserPageProps)
|
||||
<p className="meta mt-1 text-[13px]">修改成功后将在所有设备登出,需要使用新密码重新登录</p>
|
||||
</div>
|
||||
<PasswordForm />
|
||||
<LoginDevices devices={loginDevices} />
|
||||
</div>
|
||||
) : null}
|
||||
</div>
|
||||
@@ -434,6 +457,12 @@ export default async function UserPage({ params, searchParams }: UserPageProps)
|
||||
<span className="shrink-0 mt-px" style={{ color: "var(--accent)" }}>·</span>
|
||||
<span>邮箱仅你自己可见,用于安全通知。</span>
|
||||
</li>
|
||||
{effectiveTab === "security" && (
|
||||
<li className="flex gap-2">
|
||||
<span className="shrink-0 mt-px" style={{ color: "var(--accent)" }}>·</span>
|
||||
<span>「当前在线」是你正在使用的这台设备。其它记录可剔除,对方需重新输入密码才能登录。</span>
|
||||
</li>
|
||||
)}
|
||||
</ul>
|
||||
</section>
|
||||
)}
|
||||
|
||||
Reference in New Issue
Block a user