mirror of
https://gitcode.com/JianFeeeee/webui4frpc.git
synced 2026-10-03 23:53:59 +00:00
feat: 审计 CSV 导出 — 用户/API Key/集群操作日志一键下载
新增端点 (read 级, 审计 viewer 角色即可导出): - GET /audit/users.csv: 账号清单 + 最后登录时间 - GET /audit/apikeys.csv: 密钥清单 (前缀+scope+最后使用+过期) - GET /audit/cluster-log.csv: 令牌环操作日志时间线 (seq/time_utc/node/kind/detail/data_json 六列, detail 为人读摘要, data_json 保留无损原始载荷) 安全设计: - RFC4180 转义 (引号/逗号/换行) - 公式注入防御: =/+/@/tab/- 开头单元格加 ' 前缀 - ISO8601 UTC 时间戳, Excel 直接排序 - 明文密钥不可逆, 仅导出展示前缀 前端: - UsersView: 账号表/API 密钥表各加「⤓ 导出 CSV」按钮 - ClusterView: 日志导出下拉新增 CSV 选项 (走服务端生成) - api.ts: downloadAuditCsv() 统一下载管道 测试: csvEscape 全用例 / users+apikeys CSV 内容断言 / 未认证 401
This commit is contained in:
@ -117,3 +117,45 @@ func (l *ClusterLog) Snapshot() []LogEntry {
|
|||||||
copy(out, l.Log)
|
copy(out, l.Log)
|
||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// DetailOf produces a human-readable one-line summary of a log entry's
|
||||||
|
// payload, matching the frontend's detailOf formatting. Used by the audit CSV
|
||||||
|
// export and anywhere a flat text rendering of an entry is needed.
|
||||||
|
func DetailOf(e LogEntry) string {
|
||||||
|
if len(e.Data) == 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
var d map[string]any
|
||||||
|
if err := json.Unmarshal(e.Data, &d); err != nil {
|
||||||
|
return string(e.Data)
|
||||||
|
}
|
||||||
|
str := func(key string) string { s, _ := d[key].(string); return s }
|
||||||
|
switch e.Kind {
|
||||||
|
case LogForwardAdd, LogForwardRemove:
|
||||||
|
s := str("local") + " → " + str("remote")
|
||||||
|
if id := str("taskId"); id != "" {
|
||||||
|
if len(id) > 8 {
|
||||||
|
id = id[len(id)-8:]
|
||||||
|
}
|
||||||
|
s += " · " + id
|
||||||
|
}
|
||||||
|
return s
|
||||||
|
case LogNodeJoin:
|
||||||
|
if addr := str("addr"); addr != "" {
|
||||||
|
return str("node") + " @ " + addr
|
||||||
|
}
|
||||||
|
return str("node")
|
||||||
|
case LogNodeLeave:
|
||||||
|
return str("node")
|
||||||
|
case LogLeaderChange:
|
||||||
|
return "→ " + str("leader")
|
||||||
|
case LogTaskClaimed:
|
||||||
|
return fmt.Sprintf("%s→%s:%v", str("local"), str("remote"), d["port"])
|
||||||
|
default:
|
||||||
|
if len(d) > 0 {
|
||||||
|
b, _ := json.Marshal(d)
|
||||||
|
return string(b)
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
4
internal/httpapi/dist/index.html
vendored
4
internal/httpapi/dist/index.html
vendored
@ -5,8 +5,8 @@
|
|||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||||
<link rel="icon" href="/favicon.svg" type="image/svg+xml" />
|
<link rel="icon" href="/favicon.svg" type="image/svg+xml" />
|
||||||
<title>webui4frpc</title>
|
<title>webui4frpc</title>
|
||||||
<script type="module" crossorigin src="/assets/index-BUbn_fgs.js"></script>
|
<script type="module" crossorigin src="/assets/index-CepJKoxg.js"></script>
|
||||||
<link rel="stylesheet" crossorigin href="/assets/index-DQV0nqgE.css">
|
<link rel="stylesheet" crossorigin href="/assets/index-B4L3dftx.css">
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
<div id="app"></div>
|
<div id="app"></div>
|
||||||
|
|||||||
186
internal/httpapi/handlers_audit.go
Normal file
186
internal/httpapi/handlers_audit.go
Normal file
@ -0,0 +1,186 @@
|
|||||||
|
// Audit exports: CSV downloads of the evidence tables an auditor needs —
|
||||||
|
// user accounts (with last-login), API keys (with last-use), and the ring
|
||||||
|
// operation log. All read-level: exporting is exactly what a viewer/auditor
|
||||||
|
// role exists for. CSV cells are RFC4180-escaped; timestamps are ISO8601 UTC
|
||||||
|
// so spreadsheets sort them correctly.
|
||||||
|
package httpapi
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"webui4frpc/internal/cluster"
|
||||||
|
)
|
||||||
|
|
||||||
|
// csvEscape quotes a cell per RFC4180: wrap in double quotes when the value
|
||||||
|
// contains quote/comma/newline, doubling embedded quotes. Prefixing a leading
|
||||||
|
// '=' '+' '@' '\t' with an apostrophe defuses spreadsheet formula injection
|
||||||
|
// (CSV cells are data, not formulas — auditors open these in Excel).
|
||||||
|
func csvEscape(v string) string {
|
||||||
|
if v == "" {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
if strings.ContainsAny(v, ",\"\n\r") {
|
||||||
|
v = `"` + strings.ReplaceAll(v, `"`, `""`) + `"`
|
||||||
|
}
|
||||||
|
if len(v) > 0 && (v[0] == '=' || v[0] == '+' || v[0] == '@' || v[0] == '\t' || v[0] == '-') {
|
||||||
|
return "'" + v
|
||||||
|
}
|
||||||
|
return v
|
||||||
|
}
|
||||||
|
|
||||||
|
// isoTime renders unix seconds as ISO8601 UTC ("2026-08-24T12:00:00Z"); 0 →
|
||||||
|
// empty (never logged / never used).
|
||||||
|
func isoTime(unix int64) string {
|
||||||
|
if unix <= 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return time.Unix(unix, 0).UTC().Format(time.RFC3339)
|
||||||
|
}
|
||||||
|
|
||||||
|
// writeCSV sets attachment headers and streams the header row + rows.
|
||||||
|
func writeCSV(w http.ResponseWriter, filename string, header []string, rows [][]string) {
|
||||||
|
var b strings.Builder
|
||||||
|
writeRow := func(cells []string) {
|
||||||
|
for i, c := range cells {
|
||||||
|
if i > 0 {
|
||||||
|
b.WriteByte(',')
|
||||||
|
}
|
||||||
|
b.WriteString(csvEscape(c))
|
||||||
|
}
|
||||||
|
b.WriteString("\r\n")
|
||||||
|
}
|
||||||
|
writeRow(header)
|
||||||
|
for _, r := range rows {
|
||||||
|
writeRow(r)
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "text/csv; charset=utf-8")
|
||||||
|
w.Header().Set("Content-Disposition", fmt.Sprintf(`attachment; filename=%q`, filename))
|
||||||
|
_, _ = w.Write([]byte(b.String()))
|
||||||
|
}
|
||||||
|
|
||||||
|
// handleAuditUsersCsv serves GET /audit/users.csv: the account inventory with
|
||||||
|
// last-login timestamps. Admin-only? No — read-level: auditors (viewer role)
|
||||||
|
// are precisely the people who need this; password hashes were never part of
|
||||||
|
// the User JSON shape and are not included here either.
|
||||||
|
func (h *Handler) handleAuditUsersCsv(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodGet {
|
||||||
|
methodNotAllowed(w)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
users, err := h.Store.ListUsers()
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
rows := make([][]string, 0, len(users))
|
||||||
|
for _, u := range users {
|
||||||
|
rows = append(rows, []string{
|
||||||
|
strconv.FormatInt(u.ID, 10),
|
||||||
|
u.Username,
|
||||||
|
u.Role,
|
||||||
|
strconv.FormatBool(u.Enabled),
|
||||||
|
strconv.FormatBool(u.System),
|
||||||
|
isoTime(u.CreatedAt),
|
||||||
|
isoTime(u.LastLoginAt),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
writeCSV(w,
|
||||||
|
fmt.Sprintf("audit-users-%s.csv", time.Now().UTC().Format("20060102-150405")),
|
||||||
|
[]string{"id", "username", "role", "enabled", "system", "created_at", "last_login_at"},
|
||||||
|
rows)
|
||||||
|
}
|
||||||
|
|
||||||
|
// handleAuditApiKeysCsv serves GET /audit/apikeys.csv: key inventory with
|
||||||
|
// scope, last-use and expiry. The plaintext key is unrecoverable by design;
|
||||||
|
// only the display prefix is exported.
|
||||||
|
func (h *Handler) handleAuditApiKeysCsv(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodGet {
|
||||||
|
methodNotAllowed(w)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
keys, err := h.Store.ListApiKeys()
|
||||||
|
if err != nil {
|
||||||
|
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
// Resolve owning username for readability.
|
||||||
|
nameOf := map[int64]string{}
|
||||||
|
if users, err := h.Store.ListUsers(); err == nil {
|
||||||
|
for _, u := range users {
|
||||||
|
nameOf[u.ID] = u.Username
|
||||||
|
}
|
||||||
|
}
|
||||||
|
rows := make([][]string, 0, len(keys))
|
||||||
|
for _, k := range keys {
|
||||||
|
expires := ""
|
||||||
|
if k.ExpiresAt != 0 {
|
||||||
|
expires = isoTime(k.ExpiresAt)
|
||||||
|
}
|
||||||
|
rows = append(rows, []string{
|
||||||
|
strconv.FormatInt(k.ID, 10),
|
||||||
|
k.Prefix + "…",
|
||||||
|
nameOf[k.UserID],
|
||||||
|
k.Label,
|
||||||
|
k.Scope,
|
||||||
|
isoTime(k.CreatedAt),
|
||||||
|
isoTime(k.LastUsedAt),
|
||||||
|
expires,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
writeCSV(w,
|
||||||
|
fmt.Sprintf("audit-apikeys-%s.csv", time.Now().UTC().Format("20060102-150405")),
|
||||||
|
[]string{"id", "key_prefix", "owner", "label", "scope", "created_at", "last_used_at", "expires_at"},
|
||||||
|
rows)
|
||||||
|
}
|
||||||
|
|
||||||
|
// handleAuditClusterLogCsv serves GET /audit/cluster-log.csv: this node's ring
|
||||||
|
// operation log (forward add/remove, join/leave, leader changes, claims) as
|
||||||
|
// one flat CSV sorted by seq — the "who did what to the cluster" timeline.
|
||||||
|
// Data payloads are flattened into a human-readable detail column plus raw
|
||||||
|
// JSON for lossless reprocessing.
|
||||||
|
func (h *Handler) handleAuditClusterLogCsv(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodGet {
|
||||||
|
methodNotAllowed(w)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if h.Ring == nil {
|
||||||
|
http.Error(w, "ring engine not enabled", http.StatusNotFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
snap := h.Ring.Snapshot()
|
||||||
|
entries := snap.Log
|
||||||
|
rows := make([][]string, 0, len(entries))
|
||||||
|
for _, e := range entries {
|
||||||
|
rows = append(rows, []string{
|
||||||
|
strconv.FormatInt(e.Seq, 10),
|
||||||
|
isoTime(e.At),
|
||||||
|
e.Node,
|
||||||
|
e.Kind,
|
||||||
|
cluster.DetailOf(e),
|
||||||
|
rawJSON(e.Data),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
writeCSV(w,
|
||||||
|
fmt.Sprintf("audit-cluster-log-%s.csv", time.Now().UTC().Format("20060102-150405")),
|
||||||
|
[]string{"seq", "time_utc", "node", "kind", "detail", "data_json"},
|
||||||
|
rows)
|
||||||
|
}
|
||||||
|
|
||||||
|
// rawJSON renders the log entry's payload as compact JSON (empty when absent)
|
||||||
|
// for the lossless audit column.
|
||||||
|
func rawJSON(data json.RawMessage) string {
|
||||||
|
if len(data) == 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
var buf bytes.Buffer
|
||||||
|
if err := json.Compact(&buf, data); err != nil {
|
||||||
|
return string(data)
|
||||||
|
}
|
||||||
|
return buf.String()
|
||||||
|
}
|
||||||
110
internal/httpapi/handlers_audit_test.go
Normal file
110
internal/httpapi/handlers_audit_test.go
Normal file
@ -0,0 +1,110 @@
|
|||||||
|
package httpapi
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"webui4frpc/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
// newAuditHarness builds a Handler + mux with a temp store, mirroring
|
||||||
|
// TestSaveCanvasPublishesRevokeTask's setup minus the ring.
|
||||||
|
func newAuditHarness(t *testing.T) (*Handler, http.Handler) {
|
||||||
|
t.Helper()
|
||||||
|
dir := t.TempDir()
|
||||||
|
st, err := store.New(filepath.Join(dir, "test.db"))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
t.Cleanup(func() { st.Close() })
|
||||||
|
if _, err := st.CreateUser("auditor", "pw-auditor", "viewer"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if _, _, err := st.CreateApiKey(1, "ci-key", "read"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
h := &Handler{Store: st, WorkDir: dir, User: "admin", Password: "pw"}
|
||||||
|
mux, err := NewServeMux(h)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
return h, mux
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCsvEscape(t *testing.T) {
|
||||||
|
cases := []struct{ in, want string }{
|
||||||
|
{"plain", "plain"},
|
||||||
|
{"", ""},
|
||||||
|
{"a,b", `"a,b"`},
|
||||||
|
{`say "hi"`, `"say ""hi"""`},
|
||||||
|
{"line\nbreak", "\"line\nbreak\""},
|
||||||
|
{"=cmd()", "'=cmd()"}, // formula injection defused
|
||||||
|
{"+1+1", "'+1+1"}, // formula injection defused
|
||||||
|
{"@SUM(A1)", "'@SUM(A1)"}, // formula injection defused
|
||||||
|
{"-2+3", "'-2+3"}, // formula injection defused
|
||||||
|
}
|
||||||
|
for _, c := range cases {
|
||||||
|
if got := csvEscape(c.in); got != c.want {
|
||||||
|
t.Errorf("csvEscape(%q)=%q want %q", c.in, got, c.want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestIsoTimeEmpty(t *testing.T) {
|
||||||
|
if got := isoTime(0); got != "" {
|
||||||
|
t.Errorf("isoTime(0)=%q want empty", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditUsersCsv(t *testing.T) {
|
||||||
|
_, mux := newAuditHarness(t)
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/api/manager/audit/users.csv", nil)
|
||||||
|
req.SetBasicAuth("admin", "pw")
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
mux.ServeHTTP(rec, req)
|
||||||
|
if rec.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status=%d body=%s", rec.Code, rec.Body.String())
|
||||||
|
}
|
||||||
|
body := rec.Body.String()
|
||||||
|
for _, want := range []string{"id,username,role,enabled,system,created_at,last_login_at", "auditor,viewer"} {
|
||||||
|
if !strings.Contains(body, want) {
|
||||||
|
t.Errorf("CSV missing %q:\n%s", want, body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if ct := rec.Header().Get("Content-Type"); !strings.HasPrefix(ct, "text/csv") {
|
||||||
|
t.Errorf("content-type=%q", ct)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditApiKeysCsv(t *testing.T) {
|
||||||
|
_, mux := newAuditHarness(t)
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/api/manager/audit/apikeys.csv", nil)
|
||||||
|
req.SetBasicAuth("admin", "pw")
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
mux.ServeHTTP(rec, req)
|
||||||
|
if rec.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status=%d body=%s", rec.Code, rec.Body.String())
|
||||||
|
}
|
||||||
|
body := rec.Body.String()
|
||||||
|
if !strings.Contains(body, "key_prefix,owner,label,scope") {
|
||||||
|
t.Errorf("CSV header missing:\n%s", body)
|
||||||
|
}
|
||||||
|
if !strings.Contains(body, "w4f_") || !strings.Contains(body, "ci-key") {
|
||||||
|
t.Errorf("key row missing:\n%s", body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditEndpointsNeedAuth(t *testing.T) {
|
||||||
|
_, mux := newAuditHarness(t)
|
||||||
|
for _, path := range []string{"/api/manager/audit/users.csv", "/api/manager/audit/apikeys.csv"} {
|
||||||
|
req := httptest.NewRequest(http.MethodGet, path, nil)
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
mux.ServeHTTP(rec, req)
|
||||||
|
if rec.Code != http.StatusUnauthorized {
|
||||||
|
t.Errorf("%s without auth: status=%d want 401", path, rec.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@ -111,6 +111,12 @@ func NewServeMux(h *Handler) (http.Handler, error) {
|
|||||||
mux.HandleFunc(apiPrefix+"/cluster/ring", h.auth("read")(h.handleClusterRing))
|
mux.HandleFunc(apiPrefix+"/cluster/ring", h.auth("read")(h.handleClusterRing))
|
||||||
mux.HandleFunc(apiPrefix+"/node/logs", h.auth("read")(h.handleNodeLogs))
|
mux.HandleFunc(apiPrefix+"/node/logs", h.auth("read")(h.handleNodeLogs))
|
||||||
mux.HandleFunc(apiPrefix+"/cluster/logs/export", h.auth("read")(h.handleClusterLogsExport))
|
mux.HandleFunc(apiPrefix+"/cluster/logs/export", h.auth("read")(h.handleClusterLogsExport))
|
||||||
|
|
||||||
|
// Audit exports (CSV): read-level — exporting evidence is exactly what a
|
||||||
|
// viewer/auditor role exists for. RFC4180 CSV, ISO8601 UTC timestamps.
|
||||||
|
mux.HandleFunc(apiPrefix+"/audit/users.csv", h.auth("read")(h.handleAuditUsersCsv))
|
||||||
|
mux.HandleFunc(apiPrefix+"/audit/apikeys.csv", h.auth("read")(h.handleAuditApiKeysCsv))
|
||||||
|
mux.HandleFunc(apiPrefix+"/audit/cluster-log.csv", h.auth("read")(h.handleAuditClusterLogCsv))
|
||||||
mux.HandleFunc(apiPrefix+"/cluster/token", h.auth("write")(h.handleClusterToken))
|
mux.HandleFunc(apiPrefix+"/cluster/token", h.auth("write")(h.handleClusterToken))
|
||||||
mux.HandleFunc(apiPrefix+"/cluster/join", h.auth("write")(h.handleClusterJoin))
|
mux.HandleFunc(apiPrefix+"/cluster/join", h.auth("write")(h.handleClusterJoin))
|
||||||
mux.HandleFunc(apiPrefix+"/cluster/task", h.auth("write")(h.handleClusterTask))
|
mux.HandleFunc(apiPrefix+"/cluster/task", h.auth("write")(h.handleClusterTask))
|
||||||
|
|||||||
448
web/src/api.ts
448
web/src/api.ts
@ -1,232 +1,274 @@
|
|||||||
// HTTP client and API functions for webui4frpc.
|
// HTTP client and API functions for webui4frpc.
|
||||||
import type {
|
import type {
|
||||||
ApiKey,
|
ApiKey,
|
||||||
ApiKeyCreated,
|
ApiKeyCreated,
|
||||||
BinaryStatus,
|
BinaryStatus,
|
||||||
CacheResp,
|
CacheResp,
|
||||||
CanvasData,
|
CanvasData,
|
||||||
CanvasExportEnvelope,
|
CanvasExportEnvelope,
|
||||||
ClusterNodesResp,
|
ClusterNodesResp,
|
||||||
InstallResult,
|
InstallResult,
|
||||||
MeResp,
|
MeResp,
|
||||||
Remote,
|
Remote,
|
||||||
RingSnapshot,
|
RingSnapshot,
|
||||||
Settings,
|
Settings,
|
||||||
StatusResp,
|
StatusResp,
|
||||||
User,
|
User,
|
||||||
WorkerLogBundle,
|
WorkerLogBundle,
|
||||||
} from "./types";
|
} from "./types";
|
||||||
|
|
||||||
class HTTPError extends Error {
|
class HTTPError extends Error {
|
||||||
status: number;
|
status: number;
|
||||||
constructor(status: number, message: string) {
|
constructor(status: number, message: string) {
|
||||||
super(message);
|
super(message);
|
||||||
this.status = status;
|
this.status = status;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async function request<T>(url: string, options: RequestInit = {}): Promise<T> {
|
async function request<T>(url: string, options: RequestInit = {}): Promise<T> {
|
||||||
const response = await fetch(url, {
|
const response = await fetch(url, {
|
||||||
credentials: "same-origin",
|
credentials: "same-origin",
|
||||||
...options,
|
...options,
|
||||||
});
|
});
|
||||||
if (!response.ok) {
|
if (!response.ok) {
|
||||||
throw new HTTPError(response.status, `HTTP ${response.status}`);
|
throw new HTTPError(response.status, `HTTP ${response.status}`);
|
||||||
}
|
}
|
||||||
const ct = response.headers.get("content-type") || "";
|
const ct = response.headers.get("content-type") || "";
|
||||||
if (ct.includes("application/json")) {
|
if (ct.includes("application/json")) {
|
||||||
return response.json() as Promise<T>;
|
return response.json() as Promise<T>;
|
||||||
}
|
}
|
||||||
return response.text() as unknown as Promise<T>;
|
return response.text() as unknown as Promise<T>;
|
||||||
}
|
}
|
||||||
|
|
||||||
const json = (body: unknown): RequestInit => ({
|
const json = (body: unknown): RequestInit => ({
|
||||||
method: "PUT",
|
method: "PUT",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify(body),
|
body: JSON.stringify(body),
|
||||||
});
|
});
|
||||||
|
|
||||||
export const api = {
|
export const api = {
|
||||||
status: () => request<StatusResp>("/api/manager/status"),
|
status: () => request<StatusResp>("/api/manager/status"),
|
||||||
|
|
||||||
canvas: () => request<CanvasData>("/api/manager/canvas"),
|
canvas: () => request<CanvasData>("/api/manager/canvas"),
|
||||||
saveCanvas: (data: CanvasData) =>
|
saveCanvas: (data: CanvasData) =>
|
||||||
request<CanvasData>("/api/manager/canvas", json(data)),
|
request<CanvasData>("/api/manager/canvas", json(data)),
|
||||||
|
|
||||||
settings: () => request<Settings>("/api/manager/settings"),
|
settings: () => request<Settings>("/api/manager/settings"),
|
||||||
saveSettings: (s: Settings) =>
|
saveSettings: (s: Settings) =>
|
||||||
request<Settings>("/api/manager/settings", json(s)),
|
request<Settings>("/api/manager/settings", json(s)),
|
||||||
|
|
||||||
binaryStatus: () => request<BinaryStatus>("/api/manager/binary/status"),
|
binaryStatus: () => request<BinaryStatus>("/api/manager/binary/status"),
|
||||||
installBinary: (version?: string) =>
|
installBinary: (version?: string) =>
|
||||||
request<InstallResult>("/api/manager/binary/install", {
|
request<InstallResult>("/api/manager/binary/install", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: version ? JSON.stringify({ version }) : undefined,
|
body: version ? JSON.stringify({ version }) : undefined,
|
||||||
}),
|
}),
|
||||||
|
|
||||||
saveRemote: (remote: Remote) =>
|
saveRemote: (remote: Remote) =>
|
||||||
request<Remote>("/api/manager/remotes", json(remote)),
|
request<Remote>("/api/manager/remotes", json(remote)),
|
||||||
deleteRemote: (name: string) =>
|
deleteRemote: (name: string) =>
|
||||||
request<void>(`/api/manager/remotes/${encodeURIComponent(name)}`, {
|
request<void>(`/api/manager/remotes/${encodeURIComponent(name)}`, {
|
||||||
method: "DELETE",
|
method: "DELETE",
|
||||||
}),
|
}),
|
||||||
|
|
||||||
// Add a single link (POST /links). The canvas save path (saveCanvas) does a
|
// Add a single link (POST /links). The canvas save path (saveCanvas) does a
|
||||||
// wholesale link replace, so this is for incremental single-link adds from
|
// wholesale link replace, so this is for incremental single-link adds from
|
||||||
// other surfaces (e.g. a forwards list). For a cluster (non-localOnly)
|
// other surfaces (e.g. a forwards list). For a cluster (non-localOnly)
|
||||||
// forward the backend also submits a ring task so the owning node claims it.
|
// forward the backend also submits a ring task so the owning node claims it.
|
||||||
addLink: (link: {
|
addLink: (link: {
|
||||||
local: string;
|
local: string;
|
||||||
remote: string;
|
remote: string;
|
||||||
remotePort: number;
|
remotePort: number;
|
||||||
group?: string;
|
group?: string;
|
||||||
}) =>
|
}) =>
|
||||||
request<import("./types").Link>(`/api/manager/links`, {
|
request<import("./types").Link>(`/api/manager/links`, {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify(link),
|
body: JSON.stringify(link),
|
||||||
}),
|
}),
|
||||||
|
|
||||||
// Delete a single link by id. When present in the canvas save payload,
|
// Delete a single link by id. When present in the canvas save payload,
|
||||||
// links are replaced wholesale, so the typical path is "remove from
|
// links are replaced wholesale, so the typical path is "remove from
|
||||||
// canvas edges + save". This endpoint is kept for explicit removal
|
// canvas edges + save". This endpoint is kept for explicit removal
|
||||||
// (e.g. delete from a forwards list) — it also revokes cluster tasks
|
// (e.g. delete from a forwards list) — it also revokes cluster tasks
|
||||||
// for the removed forward.
|
// for the removed forward.
|
||||||
deleteLink: (id: number) =>
|
deleteLink: (id: number) =>
|
||||||
request<void>(`/api/manager/links/${id}`, { method: "DELETE" }),
|
request<void>(`/api/manager/links/${id}`, { method: "DELETE" }),
|
||||||
|
|
||||||
// Per-forward start/stop (forwards page). local-only forwards toggle the
|
// Per-forward start/stop (forwards page). local-only forwards toggle the
|
||||||
// local frpc worker; cluster forwards submit/revoke via the ring.
|
// local frpc worker; cluster forwards submit/revoke via the ring.
|
||||||
forwardStart: (local: string, remote: string, remotePort: number) =>
|
forwardStart: (local: string, remote: string, remotePort: number) =>
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/start", {
|
request<{ ok: boolean }>("/api/manager/forwards/start", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ local, remote, remotePort }),
|
body: JSON.stringify({ local, remote, remotePort }),
|
||||||
}),
|
}),
|
||||||
forwardStop: (local: string, remote: string, remotePort: number) =>
|
forwardStop: (local: string, remote: string, remotePort: number) =>
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/stop", {
|
request<{ ok: boolean }>("/api/manager/forwards/stop", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ local, remote, remotePort }),
|
body: JSON.stringify({ local, remote, remotePort }),
|
||||||
}),
|
}),
|
||||||
groupStart: (group: string) =>
|
groupStart: (group: string) =>
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/group/start", {
|
request<{ ok: boolean }>("/api/manager/forwards/group/start", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ group }),
|
body: JSON.stringify({ group }),
|
||||||
}),
|
}),
|
||||||
groupStop: (group: string) =>
|
groupStop: (group: string) =>
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/group/stop", {
|
request<{ ok: boolean }>("/api/manager/forwards/group/stop", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ group }),
|
body: JSON.stringify({ group }),
|
||||||
}),
|
}),
|
||||||
// assignGroup changes a single forward's group label (status page chip).
|
// assignGroup changes a single forward's group label (status page chip).
|
||||||
// Empty group clears the assignment (移出分组). Pure DB update, no worker.
|
// Empty group clears the assignment (移出分组). Pure DB update, no worker.
|
||||||
assignGroup: (local: string, remote: string, remotePort: number, group: string) =>
|
assignGroup: (
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/assign", {
|
local: string,
|
||||||
method: "POST",
|
remote: string,
|
||||||
headers: { "Content-Type": "application/json" },
|
remotePort: number,
|
||||||
body: JSON.stringify({ local, remote, remotePort, group }),
|
group: string,
|
||||||
}),
|
) =>
|
||||||
// deleteGroup dissolves a group: all members moved to 未分组. The group is
|
request<{ ok: boolean }>("/api/manager/forwards/assign", {
|
||||||
// just a label on links, so clearing all members is the complete delete.
|
method: "POST",
|
||||||
deleteGroup: (group: string) =>
|
headers: { "Content-Type": "application/json" },
|
||||||
request<{ ok: boolean }>("/api/manager/forwards/group/delete", {
|
body: JSON.stringify({ local, remote, remotePort, group }),
|
||||||
method: "POST",
|
}),
|
||||||
headers: { "Content-Type": "application/json" },
|
// deleteGroup dissolves a group: all members moved to 未分组. The group is
|
||||||
body: JSON.stringify({ group }),
|
// just a label on links, so clearing all members is the complete delete.
|
||||||
}),
|
deleteGroup: (group: string) =>
|
||||||
|
request<{ ok: boolean }>("/api/manager/forwards/group/delete", {
|
||||||
|
method: "POST",
|
||||||
|
headers: { "Content-Type": "application/json" },
|
||||||
|
body: JSON.stringify({ group }),
|
||||||
|
}),
|
||||||
|
|
||||||
profileStart: (name: string) =>
|
profileStart: (name: string) =>
|
||||||
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/start`, {
|
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/start`, {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
}),
|
}),
|
||||||
profileStop: (name: string) =>
|
profileStop: (name: string) =>
|
||||||
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/stop`, {
|
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/stop`, {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
}),
|
}),
|
||||||
profileRestart: (name: string) =>
|
profileRestart: (name: string) =>
|
||||||
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/restart`, {
|
request<void>(`/api/manager/profiles/${encodeURIComponent(name)}/restart`, {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
}),
|
}),
|
||||||
profileConfig: (name: string) =>
|
profileConfig: (name: string) =>
|
||||||
request<string>(`/api/manager/profiles/${encodeURIComponent(name)}/config`),
|
request<string>(`/api/manager/profiles/${encodeURIComponent(name)}/config`),
|
||||||
profileLogs: (name: string) =>
|
profileLogs: (name: string) =>
|
||||||
request<string>(`/api/manager/profiles/${encodeURIComponent(name)}/logs`),
|
request<string>(`/api/manager/profiles/${encodeURIComponent(name)}/logs`),
|
||||||
|
|
||||||
// M6: cluster nodes + binary cache management.
|
// M6: cluster nodes + binary cache management.
|
||||||
clusterNodes: () => request<ClusterNodesResp>("/api/manager/cluster/nodes"),
|
clusterNodes: () => request<ClusterNodesResp>("/api/manager/cluster/nodes"),
|
||||||
clusterCache: () => request<CacheResp>("/api/manager/cluster/cache"),
|
clusterCache: () => request<CacheResp>("/api/manager/cluster/cache"),
|
||||||
pruneCache: (keep: number) =>
|
pruneCache: (keep: number) =>
|
||||||
request<CacheResp>("/api/manager/cluster/cache", {
|
request<CacheResp>("/api/manager/cluster/cache", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ keep }),
|
body: JSON.stringify({ keep }),
|
||||||
}),
|
}),
|
||||||
|
|
||||||
// M6 token ring snapshot.
|
// M6 token ring snapshot.
|
||||||
ring: () => request<RingSnapshot>("/api/manager/cluster/ring"),
|
ring: () => request<RingSnapshot>("/api/manager/cluster/ring"),
|
||||||
|
|
||||||
// M6 cluster lifecycle (创建/加入/退出/移除).
|
// M6 cluster lifecycle (创建/加入/退出/移除).
|
||||||
// clusterCreate: reseed THIS node as a fresh standalone leader (创建集群).
|
// clusterCreate: reseed THIS node as a fresh standalone leader (创建集群).
|
||||||
clusterCreate: () =>
|
clusterCreate: () =>
|
||||||
request<RingSnapshot>("/api/manager/cluster/create", { method: "POST" }),
|
request<RingSnapshot>("/api/manager/cluster/create", { method: "POST" }),
|
||||||
// clusterJoinRing: THIS node joins the cluster at peer addr (加入集群).
|
// clusterJoinRing: THIS node joins the cluster at peer addr (加入集群).
|
||||||
// joinKey is the sponsor node's nodeKey — required for admission security.
|
// joinKey is the sponsor node's nodeKey — required for admission security.
|
||||||
clusterJoinRing: (addr: string, joinKey: string) =>
|
clusterJoinRing: (addr: string, joinKey: string) =>
|
||||||
request<RingSnapshot>("/api/manager/cluster/join-ring", {
|
request<RingSnapshot>("/api/manager/cluster/join-ring", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ addr, joinKey }),
|
body: JSON.stringify({ addr, joinKey }),
|
||||||
}),
|
}),
|
||||||
// clusterRemoveNode: publish a node-removal command (移除节点 / 退出集群[self]).
|
// clusterRemoveNode: publish a node-removal command (移除节点 / 退出集群[self]).
|
||||||
clusterRemoveNode: (id: string) =>
|
clusterRemoveNode: (id: string) =>
|
||||||
request<{ task: unknown }>("/api/manager/cluster/node-remove", {
|
request<{ task: unknown }>("/api/manager/cluster/node-remove", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ id }),
|
body: JSON.stringify({ id }),
|
||||||
}),
|
}),
|
||||||
|
|
||||||
// M7 auth/accounts/API keys/canvas export-import/worker logs.
|
// M7 auth/accounts/API keys/canvas export-import/worker logs.
|
||||||
me: () => request<MeResp>("/api/manager/me"),
|
me: () => request<MeResp>("/api/manager/me"),
|
||||||
listUsers: () => request<{ users: User[] }>("/api/manager/users"),
|
listUsers: () => request<{ users: User[] }>("/api/manager/users"),
|
||||||
createUser: (username: string, password: string, role: 'admin' | 'viewer') =>
|
createUser: (username: string, password: string, role: "admin" | "viewer") =>
|
||||||
request<User>("/api/manager/users", {
|
request<User>("/api/manager/users", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: { "Content-Type": "application/json" },
|
headers: { "Content-Type": "application/json" },
|
||||||
body: JSON.stringify({ username, password, role }),
|
body: JSON.stringify({ username, password, role }),
|
||||||
}),
|
}),
|
||||||
updateUser: (name: string, patch: { password?: string; role?: 'admin' | 'viewer'; enabled?: boolean }) =>
|
updateUser: (
|
||||||
request<User>(`/api/manager/users/${encodeURIComponent(name)}`, {
|
name: string,
|
||||||
method: "PUT",
|
patch: { password?: string; role?: "admin" | "viewer"; enabled?: boolean },
|
||||||
headers: { "Content-Type": "application/json" },
|
) =>
|
||||||
body: JSON.stringify(patch),
|
request<User>(`/api/manager/users/${encodeURIComponent(name)}`, {
|
||||||
}),
|
method: "PUT",
|
||||||
deleteUser: (name: string) =>
|
headers: { "Content-Type": "application/json" },
|
||||||
request<void>(`/api/manager/users/${encodeURIComponent(name)}`, {
|
body: JSON.stringify(patch),
|
||||||
method: "DELETE",
|
}),
|
||||||
}),
|
deleteUser: (name: string) =>
|
||||||
listApiKeys: () => request<{ apiKeys: ApiKey[] }>("/api/manager/apikeys"),
|
request<void>(`/api/manager/users/${encodeURIComponent(name)}`, {
|
||||||
createApiKey: (userId: number, label: string, scope: 'read' | 'write' | 'admin') =>
|
method: "DELETE",
|
||||||
request<ApiKeyCreated>("/api/manager/apikeys", {
|
}),
|
||||||
method: "POST",
|
listApiKeys: () => request<{ apiKeys: ApiKey[] }>("/api/manager/apikeys"),
|
||||||
headers: { "Content-Type": "application/json" },
|
createApiKey: (
|
||||||
body: JSON.stringify({ userId, label, scope }),
|
userId: number,
|
||||||
}),
|
label: string,
|
||||||
deleteApiKey: (id: number) =>
|
scope: "read" | "write" | "admin",
|
||||||
request<void>(`/api/manager/apikeys/${id}`, { method: "DELETE" }),
|
) =>
|
||||||
|
request<ApiKeyCreated>("/api/manager/apikeys", {
|
||||||
|
method: "POST",
|
||||||
|
headers: { "Content-Type": "application/json" },
|
||||||
|
body: JSON.stringify({ userId, label, scope }),
|
||||||
|
}),
|
||||||
|
deleteApiKey: (id: number) =>
|
||||||
|
request<void>(`/api/manager/apikeys/${id}`, { method: "DELETE" }),
|
||||||
|
|
||||||
// Canvas export/import (转发表 备份/还原).
|
// Canvas export/import (转发表 备份/还原).
|
||||||
exportCanvas: () => request<CanvasExportEnvelope>("/api/manager/canvas/export"),
|
exportCanvas: () =>
|
||||||
importCanvas: (data: CanvasData | CanvasExportEnvelope) =>
|
request<CanvasExportEnvelope>("/api/manager/canvas/export"),
|
||||||
request<CanvasData>("/api/manager/canvas/import", {
|
importCanvas: (data: CanvasData | CanvasExportEnvelope) =>
|
||||||
method: "POST",
|
request<CanvasData>("/api/manager/canvas/import", {
|
||||||
headers: { "Content-Type": "application/json" },
|
method: "POST",
|
||||||
body: JSON.stringify(data),
|
headers: { "Content-Type": "application/json" },
|
||||||
}),
|
body: JSON.stringify(data),
|
||||||
|
}),
|
||||||
|
|
||||||
// Worker-log bundle (HTTP fan-out across ring nodes; read-level/auditor).
|
// Worker-log bundle (HTTP fan-out across ring nodes; read-level/auditor).
|
||||||
exportWorkerLogs: () => request<WorkerLogBundle>("/api/manager/cluster/logs/export"),
|
exportWorkerLogs: () =>
|
||||||
|
request<WorkerLogBundle>("/api/manager/cluster/logs/export"),
|
||||||
|
|
||||||
|
// ---- Audit CSV exports (read-level) ----
|
||||||
|
// downloadCsv fetches a CSV endpoint with credentials and triggers a file
|
||||||
|
// download. Kept here so views don't repeat the blob plumbing.
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// downloadAuditCsv streams one of the /audit/*.csv endpoints to a file.
|
||||||
|
export async function downloadAuditCsv(
|
||||||
|
kind: "users" | "apikeys" | "cluster-log",
|
||||||
|
): Promise<void> {
|
||||||
|
const resp = await fetch(`/api/manager/audit/${kind}.csv`, {
|
||||||
|
credentials: "same-origin",
|
||||||
|
});
|
||||||
|
if (!resp.ok) throw new Error(`HTTP ${resp.status}`);
|
||||||
|
const disposition = resp.headers.get("content-disposition") || "";
|
||||||
|
const m = disposition.match(/filename="?([^";]+)"?/);
|
||||||
|
const filename = m?.[1] ?? `audit-${kind}.csv`;
|
||||||
|
const blob = new Blob([await resp.text()], {
|
||||||
|
type: "text/csv;charset=utf-8",
|
||||||
|
});
|
||||||
|
const url = URL.createObjectURL(blob);
|
||||||
|
const a = document.createElement("a");
|
||||||
|
a.href = url;
|
||||||
|
a.download = filename;
|
||||||
|
document.body.appendChild(a);
|
||||||
|
a.click();
|
||||||
|
document.body.removeChild(a);
|
||||||
|
URL.revokeObjectURL(url);
|
||||||
|
}
|
||||||
|
|||||||
@ -150,6 +150,7 @@
|
|||||||
<el-dropdown-menu>
|
<el-dropdown-menu>
|
||||||
<el-dropdown-item command="json">JSON(完整结构)</el-dropdown-item>
|
<el-dropdown-item command="json">JSON(完整结构)</el-dropdown-item>
|
||||||
<el-dropdown-item command="txt">文本(可读 TSV)</el-dropdown-item>
|
<el-dropdown-item command="txt">文本(可读 TSV)</el-dropdown-item>
|
||||||
|
<el-dropdown-item command="csv">CSV(审计用,Excel 可开)</el-dropdown-item>
|
||||||
</el-dropdown-menu>
|
</el-dropdown-menu>
|
||||||
</template>
|
</template>
|
||||||
</el-dropdown>
|
</el-dropdown>
|
||||||
@ -194,7 +195,7 @@
|
|||||||
<script setup lang="ts">
|
<script setup lang="ts">
|
||||||
import { ref, reactive, computed, onMounted, onBeforeUnmount } from 'vue'
|
import { ref, reactive, computed, onMounted, onBeforeUnmount } from 'vue'
|
||||||
import { ElMessage } from 'element-plus'
|
import { ElMessage } from 'element-plus'
|
||||||
import { api } from '../api'
|
import { api, downloadAuditCsv } from '../api'
|
||||||
import type { RingSnapshot, RingTaskInfo, RingLogEntry } from '../types'
|
import type { RingSnapshot, RingTaskInfo, RingLogEntry } from '../types'
|
||||||
|
|
||||||
const ring = ref<RingSnapshot | null>(null)
|
const ring = ref<RingSnapshot | null>(null)
|
||||||
@ -321,8 +322,18 @@ const detailOf = (e: RingLogEntry): string => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
// exportLog downloads the FULL cluster log (snapshot carries every entry) as
|
// exportLog downloads the FULL cluster log (snapshot carries every entry) as
|
||||||
// either pretty JSON (lossless) or a readable TSV text file, sorted by seq.
|
// pretty JSON (lossless), a readable TSV text file, or server-generated RFC4180
|
||||||
const exportLog = (fmt: string) => {
|
// CSV (audit deliverable, Excel-friendly) — sorted by seq.
|
||||||
|
const exportLog = async (fmt: string) => {
|
||||||
|
if (fmt === 'csv') {
|
||||||
|
// Server-side CSV: RFC4180 escaping + formula-injection defence + ISO8601 UTC.
|
||||||
|
try {
|
||||||
|
await downloadAuditCsv('cluster-log')
|
||||||
|
} catch (e: any) {
|
||||||
|
ElMessage.error('导出失败: ' + (e?.message || e))
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
const entries = [...(ring.value?.log ?? [])].sort((a, b) => a.seq - b.seq)
|
const entries = [...(ring.value?.log ?? [])].sort((a, b) => a.seq - b.seq)
|
||||||
if (!entries.length) return
|
if (!entries.length) return
|
||||||
let content = ''
|
let content = ''
|
||||||
|
|||||||
@ -10,7 +10,10 @@
|
|||||||
<section class="card">
|
<section class="card">
|
||||||
<header class="card-h">
|
<header class="card-h">
|
||||||
<h3>账号</h3>
|
<h3>账号</h3>
|
||||||
<el-button type="primary" size="small" @click="openUserCreate">+ 新建账号</el-button>
|
<div class="h-actions">
|
||||||
|
<el-button size="small" @click="exportCsv('users')">⤓ 导出 CSV</el-button>
|
||||||
|
<el-button type="primary" size="small" @click="openUserCreate">+ 新建账号</el-button>
|
||||||
|
</div>
|
||||||
</header>
|
</header>
|
||||||
<el-table :data="users" size="small" stripe empty-text="暂无账号">
|
<el-table :data="users" size="small" stripe empty-text="暂无账号">
|
||||||
<el-table-column prop="username" label="用户名" min-width="140" />
|
<el-table-column prop="username" label="用户名" min-width="140" />
|
||||||
@ -55,7 +58,10 @@
|
|||||||
<section class="card">
|
<section class="card">
|
||||||
<header class="card-h">
|
<header class="card-h">
|
||||||
<h3>API 密钥</h3>
|
<h3>API 密钥</h3>
|
||||||
<el-button type="primary" size="small" @click="openKeyCreate">+ 新建密钥</el-button>
|
<div class="h-actions">
|
||||||
|
<el-button size="small" @click="exportCsv('apikeys')">⤓ 导出 CSV</el-button>
|
||||||
|
<el-button type="primary" size="small" @click="openKeyCreate">+ 新建密钥</el-button>
|
||||||
|
</div>
|
||||||
</header>
|
</header>
|
||||||
<el-table :data="apiKeys" size="small" stripe empty-text="暂无密钥">
|
<el-table :data="apiKeys" size="small" stripe empty-text="暂无密钥">
|
||||||
<el-table-column prop="label" label="标签" min-width="140" />
|
<el-table-column prop="label" label="标签" min-width="140" />
|
||||||
@ -150,12 +156,23 @@
|
|||||||
<script setup lang="ts">
|
<script setup lang="ts">
|
||||||
import { onMounted, ref } from 'vue'
|
import { onMounted, ref } from 'vue'
|
||||||
import { ElMessage, ElMessageBox } from 'element-plus'
|
import { ElMessage, ElMessageBox } from 'element-plus'
|
||||||
import { api } from '../api'
|
import { api, downloadAuditCsv } from '../api'
|
||||||
import type { ApiKey, ApiKeyCreated, User } from '../types'
|
import type { ApiKey, ApiKeyCreated, User } from '../types'
|
||||||
|
|
||||||
const users = ref<User[]>([])
|
const users = ref<User[]>([])
|
||||||
const apiKeys = ref<ApiKey[]>([])
|
const apiKeys = ref<ApiKey[]>([])
|
||||||
|
|
||||||
|
// exportCsv streams one of the audit CSV endpoints to a file. Read-level:
|
||||||
|
// auditors pull these without any write permission.
|
||||||
|
const exportCsv = async (kind: 'users' | 'apikeys') => {
|
||||||
|
try {
|
||||||
|
await downloadAuditCsv(kind)
|
||||||
|
ElMessage.success('已导出 CSV')
|
||||||
|
} catch (e: any) {
|
||||||
|
ElMessage.error('导出失败: ' + (e?.message || e))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const loadUsers = async () => {
|
const loadUsers = async () => {
|
||||||
const r = await api.listUsers()
|
const r = await api.listUsers()
|
||||||
users.value = r.users
|
users.value = r.users
|
||||||
|
|||||||
Reference in New Issue
Block a user