Add verified camera settings, family version recovery and account self service

This commit is contained in:
Codex
2026-10-04 04:52:39 +08:00
parent 56a24c80e2
commit 96f0ef31fc
18 changed files with 969 additions and 37 deletions
+26
View File
@@ -4,11 +4,13 @@ import hmac
import json
import re
import secrets
import time
class Accounts:
def __init__(self, app):
self.a = app
self.password_attempts = {}
def initialize(self):
a = self.a
@@ -99,6 +101,30 @@ class Accounts:
a.audit('更新账号' if old else '建立账号', username)
return self.public(user)
def change_password(self, data, actor):
a = self.a
with a.LOCK:
current = a.get_object('users', actor['id'])
if not current or current['disabled']:
raise a.Problem('请重新登录', 401)
now = time.time()
self.password_attempts = {k: v for k, v in self.password_attempts.items() if v[1] > now}
count, expiry = self.password_attempts.get(current['id'], (0, now + 900))
if count >= 8:
raise a.Problem('当前密码尝试次数过多,请 15 分钟后重试', 429)
if not self.verify(current['username'], data.get('currentPassword')):
self.password_attempts[current['id']] = (count + 1, expiry)
raise a.Problem('当前密码不正确', 403)
if data.get('newPassword') == data.get('currentPassword'):
raise a.Problem('新密码不能与当前密码相同')
credentials = self.password(data.get('newPassword'))
with a.DB:
a.DB.execute('UPDATE users SET body=? WHERE id=?', (json.dumps(dict(current, **credentials)), current['id']))
a.DB.execute('DELETE FROM sessions WHERE user_id=?', (current['id'],))
self.password_attempts.pop(current['id'], None)
a.audit('本人修改密码', current['username'])
return {'ok': True}
def camera(self, user, camera):
if not camera:
raise self.a.Problem('摄像头不存在', 404)