完善站点运营设置:分路由管理、登录可见评论、邮件模板内联与关闭注册 SSR。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-23 00:17:00 +08:00
parent acde7ee288
commit 6f054a903c
98 changed files with 8239 additions and 2073 deletions

View File

@@ -1,7 +1,10 @@
package router
import (
"context"
"os"
"path/filepath"
"strings"
"time"
"github.com/freefire/jiang13-bbs/config"
@@ -23,6 +26,13 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
}
r := gin.New()
var proxies []string
if v := os.Getenv("TRUSTED_PROXIES"); v != "" {
proxies = strings.Split(v, ",")
}
if err := r.SetTrustedProxies(proxies); err != nil {
return nil, err
}
// 大附件落盘到临时文件,避免 multipart 整文件进内存(默认 32MiB)
r.MaxMultipartMemory = 4 << 20
r.Use(gin.Recovery())
@@ -44,6 +54,8 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
authSvc := service.NewAuthService(model.DB, cfg.JWTSecret)
boardSvc := service.NewBoardService(model.DB)
settingSvc := service.NewSettingService(model.DB)
ops := service.NewOperations(model.DB, cfg)
go ops.Run(context.Background())
postSvc := service.NewPostService(model.DB).WithSetting(settingSvc).WithDevMode(cfg.DevMode)
commentSvc := service.NewCommentService(model.DB)
likeSvc := service.NewLikeService(model.DB)
@@ -54,6 +66,8 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
sitePageSvc := service.NewSitePageService(model.DB)
uploadSvc := service.NewUploadService(model.DB, filepath.Join(cfg.DataDir, "uploads")).WithSetting(settingSvc)
postFileSvc := service.NewPostFileService(model.DB, filepath.Join(cfg.DataDir, "private")).WithSetting(settingSvc)
uploadSvc.WithOperations(ops)
postFileSvc.WithOperations(ops)
pointsSvc := service.NewPointsService(model.DB)
adminUserSvc := service.NewAdminUserService(model.DB)
moderationSvc := service.NewModerationService(model.DB, notifSvc)
@@ -69,6 +83,7 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
limiter := service.DefaultRateLimiter()
h := &handler.Handlers{
Ops: ops,
Cfg: cfg,
Hub: realtime.NewHub(),
Auth: authSvc,
@@ -105,6 +120,7 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
service.StartLikeNotifyFlusher(notifSvc)
authMW := middleware.NewAuthMiddleware(authSvc)
r.Use(authMW.OptionalAuth(), h.RuntimeGuard, h.BusinessQuota)
// 上传文件静态服务(data/uploads → /uploads)
r.Static("/uploads", filepath.Join(cfg.DataDir, "uploads"))
@@ -134,6 +150,10 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
pubAPI.GET("/pages", h.SitePagesList)
pubAPI.GET("/pages/:slug", h.SitePageDetail)
pubAPI.GET("/settings", h.PublicSettings)
pubAPI.GET("/site-state", h.SiteState)
pubAPI.GET("/media/:object", h.PublicObject)
pubAPI.POST("/auth/code", middleware.CSRFMiddleware(), h.SendEmailCode)
pubAPI.POST("/auth/reset-password", middleware.CSRFMiddleware(), h.ResetPassword)
pubAPI.POST("/telemetry/pageview", middleware.CSRFMiddleware(), h.TelemetryPageView)
pubAPI.POST("/register", middleware.RateLimitMiddleware(limiter, service.RateRegister), h.Register)
pubAPI.POST("/login", middleware.RateLimitMiddleware(limiter, service.RateLogin), h.Login)
@@ -264,8 +284,15 @@ func Setup(cfg *config.Config) (*gin.Engine, error) {
announceAPI.PUT("/pages/:id", h.AdminUpdateSitePage)
announceAPI.DELETE("/pages/:id", h.AdminDeleteSitePage)
// 站点外观设置(超级管理员/站长);含 timeline_git_import
// 站点设置(超级管理员/站长)
staffAPI.GET("/settings", authMW.RequirePerm(service.PermSettings), h.AdminGetSettings)
opsAPI := staffAPI.Group("/settings/modules", authMW.RequirePerm(service.PermSettings))
opsAPI.GET("/:module", h.ReadModule)
opsAPI.PUT("/:module", h.SaveModule)
opsAPI.POST("/:module/test", h.TestModule)
opsAPI.GET("/:module/records", h.ModuleRecords)
staffAPI.GET("/diagnostics", authMW.RequirePerm(service.PermSettings), h.Diagnostics)
staffAPI.POST("/maintenance/actions", authMW.RequirePerm(service.PermSettings), h.MaintenanceAction)
staffAPI.PUT("/settings", authMW.RequirePerm(service.PermSettings), h.UpdateSettings)
staffAPI.POST("/upload/background", authMW.RequirePerm(service.PermSettings), middleware.RateLimitMiddleware(limiter, service.RateUpload), h.UploadBackground)
staffAPI.POST("/upload/background/from-media", authMW.RequirePerm(service.PermSettings), middleware.RateLimitMiddleware(limiter, service.RateUpload), h.UploadBackgroundFromMedia)