feat(hide): 密码可见隐藏块,发帖双栏预览与门禁体验修复

增加密码解锁与游客签名 cookie;发帖页对齐 1440 并默认双栏预览;修复 locked 解析、按钮对比度与回复聚焦。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-17 05:46:42 +08:00
parent 01e2fd05ca
commit c44b0efa7d
23 changed files with 911 additions and 132 deletions

View File

@@ -3,11 +3,31 @@ package middleware
import (
"crypto/subtle"
"net/http"
"time"
"github.com/freefire/jiang13-bbs/service"
"github.com/gin-gonic/gin"
)
// EnsureCSRFCookie 若请求尚无 CSRF cookie 则签发一枚(游客也可拿到,供公开写接口双提交)。
// 不改写已有 cookie;生命周期与 refresh 一致(7 天)。
func EnsureCSRFCookie(secure bool) gin.HandlerFunc {
return func(c *gin.Context) {
if raw, err := c.Cookie(service.CSRFCookieName); err != nil || raw == "" {
http.SetCookie(c.Writer, &http.Cookie{
Name: service.CSRFCookieName,
Value: service.GenerateCSRFToken(),
Path: "/",
MaxAge: int((7 * 24 * time.Hour).Seconds()),
HttpOnly: false,
Secure: secure,
SameSite: http.SameSiteLaxMode,
})
}
c.Next()
}
}
// CSRFMiddleware CSRF 防护中间件
// 对 POST/PUT/DELETE 等状态变更请求,校验 X-CSRF-Token header 与 cookie 中的 CSRF token 是否一致
func CSRFMiddleware() gin.HandlerFunc {