feat(auth): 接入 auth-hub 统一登录,网页登录与 Garmin 同步彻底分离
网页身份改由 auth-hub 做 OAuth2 + PKCE 单点登录,本地邮箱/密码登录与注册整条链路删除 (routes/auth.py、auth.py 的密码哈希、config.py 的 ALLOW_REGISTRATION)。Garmin 账号绑定/ 同步保持完全独立、可选:routes/garmin.py 不再直接查 users 表,Garmin 邮箱回退统一走新增 的 services/garmin.py::get_remembered_email()(优先读 garmin_tokens 当前绑定,兼容早期账号 落在 users.garmin_email 的历史值),彻底把「你是谁」和「你绑没绑 Garmin」两件事拆开。 - db.py: users 表新增 auth_hub_sub/auth_hub_username,MIGRATIONS 补上这两列(此前遗漏导致 已存在的生产 MariaDB 表永远不会自动加列);同时把历史遗留的 garmin_email/ garmin_password_hash NOT NULL 约束在线迁移为可空,因为新账号不再在注册时收集这些字段。 - routes/auth.py: 修掉 /callback 路由重复拼接 /api/auth 前缀导致 404 的 bug。 - client: LoginPage 去掉本地登录/注册标签页,只保留 auth-hub 统一登录;登录成功/失败后都 用 history.replaceState 清理地址栏,修掉 Framework7 browserHistory 读取 /auth/callback?code=... 导致「找不到页面」的问题。 - 新增 test_auth_hub_client.py 锁定 find_or_create_user 按 auth_hub_sub 幂等——生产上曾经因为 这个函数在没有该测试保护时被测试触发,误建过一个空账号,靠手工核对 health_data 计数才发现。 - 生产 auth-hub 侧另行为该项目注册了正式 client(未随本次提交变更,凭证只存在服务器 .env)。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,14 +1,15 @@
|
||||
"""
|
||||
Smoke test for the Flask backend (SQLite).
|
||||
|
||||
Exercises the full request path: register -> login -> authenticated reads for
|
||||
health summary/steps/heart-rate/sleep/activities, analysis trends +
|
||||
recommendations, and Garmin sync status. Run: `python tests/smoke.py`.
|
||||
Exercises the full request path: a user account (as if signed in through
|
||||
auth-hub) -> authenticated reads for health summary/steps/heart-rate/sleep/
|
||||
activities, analysis trends + recommendations, and Garmin sync status.
|
||||
Run: `python tests/smoke.py`.
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
import tempfile
|
||||
import json
|
||||
import uuid
|
||||
|
||||
# Configure the backend BEFORE importing app/config.
|
||||
_TMP_DB = os.path.join(tempfile.mkdtemp(), "smoke.db")
|
||||
@@ -21,6 +22,7 @@ sys.path.insert(0, os.path.dirname(os.path.dirname(os.path.abspath(__file__))))
|
||||
|
||||
from app import create_app # noqa: E402
|
||||
from db import execute # noqa: E402
|
||||
from auth import sign_token # noqa: E402
|
||||
|
||||
app = create_app()
|
||||
client = app.test_client()
|
||||
@@ -42,28 +44,19 @@ def auth_headers(token):
|
||||
return {"Authorization": f"Bearer {token}", "Content-Type": "application/json"}
|
||||
|
||||
|
||||
print("\n[1] Auth: register + login")
|
||||
r = client.post(
|
||||
"/api/auth/register",
|
||||
json={"email": "tester@example.com", "garminEmail": "gm@example.com", "garminPassword": "secret123"},
|
||||
print("\n[1] Auth: user account (as if signed in through auth-hub)")
|
||||
uid = str(uuid.uuid4())
|
||||
token = sign_token(uid)
|
||||
execute(
|
||||
"INSERT INTO users (id, email, auth_hub_username, jwt_token) VALUES (?, ?, ?, ?)",
|
||||
[uid, "tester@example.com", "tester@example.com", token],
|
||||
)
|
||||
check("register 201", r.status_code == 201, r.get_data(as_text=True))
|
||||
token = (r.get_json() or {}).get("token")
|
||||
check("register returns token", bool(token))
|
||||
|
||||
r = client.post("/api/auth/login", json={"email": "tester@example.com", "password": "secret123"})
|
||||
check("login 200", r.status_code == 200, r.get_data(as_text=True))
|
||||
token = (r.get_json() or {}).get("token")
|
||||
check("login returns token", bool(token))
|
||||
|
||||
r = client.post("/api/auth/login", json={"email": "tester@example.com", "password": "wrong"})
|
||||
check("login rejects bad password (401)", r.status_code == 401)
|
||||
check("user created", bool(uid))
|
||||
|
||||
r = client.get("/api/health/summary")
|
||||
check("unauthenticated read 401", r.status_code == 401)
|
||||
|
||||
print("\n[2] Seed health data (3 days)")
|
||||
uid = (client.post("/api/auth/login", json={"email": "tester@example.com", "password": "secret123"}).get_json())["id"]
|
||||
for i, (steps, hr, sleep, stress) in enumerate([(6500, 70, 6.2, 55), (9000, 62, 7.5, 40), (7500, 68, 6.8, 48)]):
|
||||
date = f"2026-08-{20 + i}"
|
||||
execute(
|
||||
|
||||
Reference in New Issue
Block a user