feat(hide): 密码可见隐藏块,发帖双栏预览与门禁体验修复
增加密码解锁与游客签名 cookie;发帖页对齐 1440 并默认双栏预览;修复 locked 解析、按钮对比度与回复聚焦。 Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -6,47 +6,59 @@ import (
|
||||
"fmt"
|
||||
"strconv"
|
||||
"strings"
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
const (
|
||||
HideKindLogin = "login"
|
||||
HideKindReply = "reply"
|
||||
HideKindPoints = "points"
|
||||
HideKindLogin = "login"
|
||||
HideKindReply = "reply"
|
||||
HideKindPoints = "points"
|
||||
HideKindPassword = "password"
|
||||
)
|
||||
|
||||
const (
|
||||
// MaxHidePasswordLen 密码可见块密码最大长度(字符)
|
||||
MaxHidePasswordLen = 64
|
||||
// MinHidePasswordLen 密码最小长度
|
||||
MinHidePasswordLen = 1
|
||||
)
|
||||
|
||||
// HideBlock 正文中的一段隐藏内容
|
||||
type HideBlock struct {
|
||||
Kind string // login | reply | points
|
||||
Points int // 仅 points 有效
|
||||
Body string // 块内 Markdown(不含开闭标记行)
|
||||
Start int // 开标记行在 lines 中的下标
|
||||
End int // 闭标记行在 lines 中的下标(含)
|
||||
Locked bool // 开标记是否已带 locked(脱敏输出)
|
||||
Kind string // login | reply | points | password
|
||||
Points int // 仅 points 有效
|
||||
Password string // 仅 password 有效(原文;脱敏输出时清空)
|
||||
Body string // 块内 Markdown(不含开闭标记行)
|
||||
Start int // 开标记行在 lines 中的下标
|
||||
End int // 闭标记行在 lines 中的下标(含)
|
||||
Locked bool // 开标记是否已带 locked(脱敏输出)
|
||||
Index int // 在全文隐藏块列表中的下标(0-based)
|
||||
}
|
||||
|
||||
// DerivedAccess 由正文隐藏块派生的帖级可见性
|
||||
type DerivedAccess struct {
|
||||
Access string // public | login | reply | points | mixed
|
||||
Access string // public | login | reply | points | password | mixed
|
||||
Points int // 所有积分块价格之和
|
||||
}
|
||||
|
||||
// ViewerCaps 读者对隐藏块的能力(由 service 填充)
|
||||
type ViewerCaps struct {
|
||||
Bypass bool // 作者 / 版主
|
||||
LoggedIn bool
|
||||
HasReplied bool
|
||||
PointsPaid bool // 已支付本帖积分解锁
|
||||
Bypass bool // 作者 / 版主
|
||||
LoggedIn bool
|
||||
HasReplied bool
|
||||
PointsPaid bool // 已支付本帖积分解锁
|
||||
PasswordUnlocked map[int]bool // 已凭密码解锁的隐藏块下标
|
||||
}
|
||||
|
||||
var (
|
||||
ErrHideNested = errors.New("隐藏块不可嵌套")
|
||||
ErrHideUnclosed = errors.New("隐藏块未正确闭合")
|
||||
ErrHideInvalid = errors.New("隐藏块语法无效")
|
||||
ErrHidePointsNeed = errors.New("积分可见块须指定 1–100000 的积分")
|
||||
ErrHideNested = errors.New("隐藏块不可嵌套")
|
||||
ErrHideUnclosed = errors.New("隐藏块未正确闭合")
|
||||
ErrHideInvalid = errors.New("隐藏块语法无效")
|
||||
ErrHidePointsNeed = errors.New("积分可见块须指定 1–100000 的积分")
|
||||
ErrHidePasswordNeed = errors.New("密码可见块须设置 1–64 字符且不含空格的密码")
|
||||
)
|
||||
|
||||
// ParseHideBlocks 扫描正文中的 :::hide 块(忽略代码围栏内伪语法)。
|
||||
// 校验失败返回 error(用于 Create/Update)。
|
||||
func ParseHideBlocks(content string) ([]HideBlock, error) {
|
||||
lines := splitLines(content)
|
||||
var blocks []HideBlock
|
||||
@@ -65,7 +77,7 @@ func ParseHideBlocks(content string) ([]HideBlock, error) {
|
||||
continue
|
||||
}
|
||||
|
||||
if kind, pts, locked, ok := parseOpenMarker(trimmed); ok {
|
||||
if kind, pts, pwd, locked, ok := parseOpenMarker(trimmed); ok {
|
||||
j := i + 1
|
||||
bodyLines := make([]string, 0)
|
||||
foundClose := false
|
||||
@@ -83,7 +95,7 @@ func ParseHideBlocks(content string) ([]HideBlock, error) {
|
||||
j++
|
||||
continue
|
||||
}
|
||||
if _, _, _, isOpen := parseOpenMarker(inner); isOpen {
|
||||
if _, _, _, _, isOpen := parseOpenMarker(inner); isOpen {
|
||||
return nil, ErrHideNested
|
||||
}
|
||||
if isCloseMarker(inner) {
|
||||
@@ -101,13 +113,23 @@ func ParseHideBlocks(content string) ([]HideBlock, error) {
|
||||
return nil, ErrHidePointsNeed
|
||||
}
|
||||
}
|
||||
if kind == HideKindPassword {
|
||||
// 已 locked 的脱敏行无密码,仅服务端原文必须带合法密码
|
||||
if !locked {
|
||||
if err := validatePassword(pwd); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
}
|
||||
blocks = append(blocks, HideBlock{
|
||||
Kind: kind,
|
||||
Points: pts,
|
||||
Body: strings.Join(bodyLines, "\n"),
|
||||
Start: i,
|
||||
End: j,
|
||||
Locked: locked,
|
||||
Kind: kind,
|
||||
Points: pts,
|
||||
Password: pwd,
|
||||
Body: strings.Join(bodyLines, "\n"),
|
||||
Start: i,
|
||||
End: j,
|
||||
Locked: locked,
|
||||
Index: len(blocks),
|
||||
})
|
||||
i = j + 1
|
||||
continue
|
||||
@@ -153,7 +175,7 @@ func DeriveAccessFromContent(content string) (DerivedAccess, error) {
|
||||
}
|
||||
|
||||
// SanitizeForViewer 按读者能力脱敏:未满足条件的块清空正文并加 locked。
|
||||
// fullyLocked 表示读者当前看不到任何可见正文(整篇都在锁块里或公开区为空)。
|
||||
// 密码块即使已解锁,也不向读者回传明文密码(开标记写成 :::hide password)。
|
||||
func SanitizeForViewer(content string, caps ViewerCaps) (sanitized string, fullyLocked bool) {
|
||||
blocks, err := ParseHideBlocks(content)
|
||||
if err != nil {
|
||||
@@ -180,7 +202,7 @@ func SanitizeForViewer(content string, caps ViewerCaps) (sanitized string, fully
|
||||
}
|
||||
|
||||
if blockUnlocked(b, caps) {
|
||||
out = append(out, openMarkerLine(b.Kind, b.Points, false))
|
||||
out = append(out, openMarkerLine(b.Kind, b.Points, "", false))
|
||||
if b.Body != "" {
|
||||
out = append(out, splitLines(b.Body)...)
|
||||
if strings.TrimSpace(b.Body) != "" {
|
||||
@@ -189,7 +211,7 @@ func SanitizeForViewer(content string, caps ViewerCaps) (sanitized string, fully
|
||||
}
|
||||
out = append(out, ":::")
|
||||
} else {
|
||||
out = append(out, openMarkerLine(b.Kind, b.Points, true))
|
||||
out = append(out, openMarkerLine(b.Kind, b.Points, "", true))
|
||||
out = append(out, ":::")
|
||||
}
|
||||
cursor = b.End + 1
|
||||
@@ -204,10 +226,28 @@ func SanitizeForViewer(content string, caps ViewerCaps) (sanitized string, fully
|
||||
return strings.Join(out, "\n"), !anyVisible
|
||||
}
|
||||
|
||||
// MatchPasswordBlocks 返回密码匹配的隐藏块下标
|
||||
func MatchPasswordBlocks(content, password string) ([]int, error) {
|
||||
blocks, err := ParseHideBlocks(content)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var hit []int
|
||||
for _, b := range blocks {
|
||||
if b.Kind != HideKindPassword {
|
||||
continue
|
||||
}
|
||||
if constantTimeEqual(b.Password, password) {
|
||||
hit = append(hit, b.Index)
|
||||
}
|
||||
}
|
||||
return hit, nil
|
||||
}
|
||||
|
||||
// WrapContentAsHide 将整篇正文包进单一隐藏块(旧帖迁移用)
|
||||
func WrapContentAsHide(kind string, points int, content string) string {
|
||||
body := strings.TrimRight(content, "\n")
|
||||
open := openMarkerLine(kind, points, false)
|
||||
open := openMarkerLine(kind, points, "", false)
|
||||
if body == "" {
|
||||
return open + "\n:::\n"
|
||||
}
|
||||
@@ -231,12 +271,15 @@ func blockUnlocked(b HideBlock, caps ViewerCaps) bool {
|
||||
return caps.HasReplied
|
||||
case HideKindPoints:
|
||||
return caps.PointsPaid
|
||||
case HideKindPassword:
|
||||
return caps.PasswordUnlocked != nil && caps.PasswordUnlocked[b.Index]
|
||||
default:
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
func openMarkerLine(kind string, points int, locked bool) string {
|
||||
// openMarkerLine 生成开标记。密码仅在原文存储时写入;对外脱敏输出传空 password。
|
||||
func openMarkerLine(kind string, points int, password string, locked bool) string {
|
||||
var b strings.Builder
|
||||
b.WriteString(":::hide ")
|
||||
b.WriteString(kind)
|
||||
@@ -244,50 +287,72 @@ func openMarkerLine(kind string, points int, locked bool) string {
|
||||
b.WriteByte(' ')
|
||||
b.WriteString(strconv.Itoa(points))
|
||||
}
|
||||
if kind == HideKindPassword && password != "" && !locked {
|
||||
b.WriteByte(' ')
|
||||
b.WriteString(password)
|
||||
}
|
||||
if locked {
|
||||
b.WriteString(" locked")
|
||||
}
|
||||
return b.String()
|
||||
}
|
||||
|
||||
func parseOpenMarker(trimmed string) (kind string, points int, locked bool, ok bool) {
|
||||
// parseOpenMarker 解析 :::hide <kind> [points|password] [locked]
|
||||
func parseOpenMarker(trimmed string) (kind string, points int, password string, locked bool, ok bool) {
|
||||
if !strings.HasPrefix(trimmed, ":::hide") {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
rest := strings.TrimSpace(trimmed[len(":::hide"):])
|
||||
if rest == "" {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
parts := strings.Fields(rest)
|
||||
if len(parts) == 0 {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
kind = parts[0]
|
||||
switch kind {
|
||||
case HideKindLogin, HideKindReply, HideKindPoints:
|
||||
case HideKindLogin, HideKindReply, HideKindPoints, HideKindPassword:
|
||||
default:
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
idx := 1
|
||||
if kind == HideKindPoints {
|
||||
if idx >= len(parts) {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
n, err := strconv.Atoi(parts[idx])
|
||||
if err != nil {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
points = n
|
||||
idx++
|
||||
} else if kind == HideKindPassword {
|
||||
// 允许::::hide password locked(脱敏)或 :::hide password <pwd> [locked]
|
||||
if idx < len(parts) && parts[idx] != "locked" {
|
||||
password = parts[idx]
|
||||
idx++
|
||||
}
|
||||
}
|
||||
for ; idx < len(parts); idx++ {
|
||||
if parts[idx] == "locked" {
|
||||
locked = true
|
||||
} else {
|
||||
return "", 0, false, false
|
||||
return "", 0, "", false, false
|
||||
}
|
||||
}
|
||||
return kind, points, locked, true
|
||||
return kind, points, password, locked, true
|
||||
}
|
||||
|
||||
func validatePassword(pwd string) error {
|
||||
if pwd == "" || strings.ContainsAny(pwd, " \t") {
|
||||
return ErrHidePasswordNeed
|
||||
}
|
||||
n := utf8.RuneCountInString(pwd)
|
||||
if n < MinHidePasswordLen || n > MaxHidePasswordLen {
|
||||
return ErrHidePasswordNeed
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func isCloseMarker(trimmed string) bool {
|
||||
@@ -316,9 +381,22 @@ func ValidateHideContent(content string) error {
|
||||
return fmt.Errorf("隐藏块未正确闭合,请检查 ::: 标记")
|
||||
case errors.Is(err, ErrHidePointsNeed):
|
||||
return fmt.Errorf("积分可见块须指定 1–100000 的积分")
|
||||
case errors.Is(err, ErrHidePasswordNeed):
|
||||
return fmt.Errorf("密码可见块须设置 1–64 字符且不含空格的密码")
|
||||
case errors.Is(err, ErrHideInvalid):
|
||||
return fmt.Errorf("隐藏块语法无效")
|
||||
default:
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
func constantTimeEqual(a, b string) bool {
|
||||
if len(a) != len(b) {
|
||||
return false
|
||||
}
|
||||
var v byte
|
||||
for i := 0; i < len(a); i++ {
|
||||
v |= a[i] ^ b[i]
|
||||
}
|
||||
return v == 0
|
||||
}
|
||||
|
||||
@@ -111,6 +111,56 @@ func TestCodeInsideHide(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestParsePasswordAndSanitize(t *testing.T) {
|
||||
src := "公开\n\n:::hide password secret1\n密码内容\n:::\n"
|
||||
blocks, err := ParseHideBlocks(src)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(blocks) != 1 || blocks[0].Kind != HideKindPassword || blocks[0].Password != "secret1" {
|
||||
t.Fatalf("%+v", blocks)
|
||||
}
|
||||
d := DeriveAccess(blocks)
|
||||
if d.Access != "password" {
|
||||
t.Fatalf("access=%s", d.Access)
|
||||
}
|
||||
out, fully := SanitizeForViewer(src, ViewerCaps{})
|
||||
if fully {
|
||||
t.Fatal("public visible")
|
||||
}
|
||||
if strings.Contains(out, "secret1") || strings.Contains(out, "密码内容") {
|
||||
t.Fatalf("leaked: %q", out)
|
||||
}
|
||||
if !strings.Contains(out, ":::hide password locked") {
|
||||
t.Fatalf("%q", out)
|
||||
}
|
||||
out2, _ := SanitizeForViewer(src, ViewerCaps{PasswordUnlocked: map[int]bool{0: true}})
|
||||
if !strings.Contains(out2, "密码内容") {
|
||||
t.Fatalf("unlock failed: %q", out2)
|
||||
}
|
||||
if strings.Contains(out2, "secret1") {
|
||||
t.Fatalf("password leaked after unlock: %q", out2)
|
||||
}
|
||||
}
|
||||
|
||||
func TestMatchPasswordBlocks(t *testing.T) {
|
||||
src := ":::hide password aaa\nA\n:::\n\n:::hide password bbb\nB\n:::\n"
|
||||
hit, err := MatchPasswordBlocks(src, "bbb")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(hit) != 1 || hit[0] != 1 {
|
||||
t.Fatalf("%v", hit)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPasswordNeed(t *testing.T) {
|
||||
_, err := ParseHideBlocks(":::hide password\n无密码\n:::\n")
|
||||
if err != ErrHidePasswordNeed {
|
||||
t.Fatalf("got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWrapContentAsHide(t *testing.T) {
|
||||
got := WrapContentAsHide("points", 20, "旧正文")
|
||||
if !strings.HasPrefix(got, ":::hide points 20\n") {
|
||||
|
||||
Reference in New Issue
Block a user