Fix family publishing, concurrent edits and session consistency

This commit is contained in:
Codex
2026-10-03 20:27:11 +08:00
parent 80f8bd72af
commit 56a24c80e2
12 changed files with 210 additions and 38 deletions
+9 -5
View File
@@ -493,11 +493,14 @@ class Handler(BaseHTTPRequestHandler):
if self.user['role'] != 'admin':
raise Problem('此操作需要管理员权限', 403)
def body(self):
def body(self, maximum=16384):
if self.headers.get_content_type() != 'application/json':
raise Problem('请求需要 JSON 格式')
n = int(self.headers.get('Content-Length', '0'))
if not 0 < n <= 16384:
try:
n = int(self.headers.get('Content-Length', '0'))
except ValueError:
raise Problem('请求长度不正确')
if not 0 < n <= maximum:
raise Problem('请求长度不正确')
try:
data = json.loads(self.rfile.read(n))
@@ -553,9 +556,10 @@ class Handler(BaseHTTPRequestHandler):
def do_POST(self):
try:
self.validate_origin()
path = url.urlsplit(self.path).path
data = self.body()
# 12,000 Chinese characters plus JSON escapes and linked people exceed 16 KiB.
data = self.body(131072 if path == '/api/family/event' else 16384)
self.validate_origin()
if path in ('/api/login', '/api/setup'):
self.login(data, path == '/api/setup')
return