feat(auth): 接入 auth-hub 统一登录,网页登录与 Garmin 同步彻底分离
网页身份改由 auth-hub 做 OAuth2 + PKCE 单点登录,本地邮箱/密码登录与注册整条链路删除 (routes/auth.py、auth.py 的密码哈希、config.py 的 ALLOW_REGISTRATION)。Garmin 账号绑定/ 同步保持完全独立、可选:routes/garmin.py 不再直接查 users 表,Garmin 邮箱回退统一走新增 的 services/garmin.py::get_remembered_email()(优先读 garmin_tokens 当前绑定,兼容早期账号 落在 users.garmin_email 的历史值),彻底把「你是谁」和「你绑没绑 Garmin」两件事拆开。 - db.py: users 表新增 auth_hub_sub/auth_hub_username,MIGRATIONS 补上这两列(此前遗漏导致 已存在的生产 MariaDB 表永远不会自动加列);同时把历史遗留的 garmin_email/ garmin_password_hash NOT NULL 约束在线迁移为可空,因为新账号不再在注册时收集这些字段。 - routes/auth.py: 修掉 /callback 路由重复拼接 /api/auth 前缀导致 404 的 bug。 - client: LoginPage 去掉本地登录/注册标签页,只保留 auth-hub 统一登录;登录成功/失败后都 用 history.replaceState 清理地址栏,修掉 Framework7 browserHistory 读取 /auth/callback?code=... 导致「找不到页面」的问题。 - 新增 test_auth_hub_client.py 锁定 find_or_create_user 按 auth_hub_sub 幂等——生产上曾经因为 这个函数在没有该测试保护时被测试触发,误建过一个空账号,靠手工核对 health_data 计数才发现。 - 生产 auth-hub 侧另行为该项目注册了正式 client(未随本次提交变更,凭证只存在服务器 .env)。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -305,16 +305,51 @@ class TestTokenStore:
|
||||
assert len(rows) == 1
|
||||
assert garmin_svc.load_token(user["id"]) == "second"
|
||||
|
||||
def test_tokens_are_per_user(self, db, user, client):
|
||||
def test_tokens_are_per_user(self, db, user, make_user):
|
||||
garmin_svc.save_token(user["id"], "mine", "g@example.com")
|
||||
other = client.post(
|
||||
"/api/auth/register",
|
||||
json={"email": "o@example.com", "garminEmail": "og@example.com",
|
||||
"garminPassword": "pw123456"},
|
||||
).get_json()
|
||||
other = make_user("o@example.com")
|
||||
assert garmin_svc.has_token(other["id"]) is False
|
||||
|
||||
|
||||
class TestRememberedEmail:
|
||||
"""`garmin_tokens` is the live Garmin binding; `users.garmin_email` is a
|
||||
legacy column kept only for accounts that bound Garmin before that table
|
||||
existed and have not signed in again since (see services/garmin.py)."""
|
||||
|
||||
def test_none_when_never_bound(self, db, user):
|
||||
assert garmin_svc.get_remembered_email(user["id"]) == ""
|
||||
|
||||
def test_reads_from_the_current_binding(self, db, user):
|
||||
garmin_svc.save_token(user["id"], "tok", "current@example.com")
|
||||
assert garmin_svc.get_remembered_email(user["id"]) == "current@example.com"
|
||||
|
||||
def test_current_binding_wins_over_the_legacy_column(self, db, user):
|
||||
db.execute(
|
||||
"UPDATE users SET garmin_email = ? WHERE id = ?",
|
||||
["legacy@example.com", user["id"]],
|
||||
)
|
||||
garmin_svc.save_token(user["id"], "tok", "current@example.com")
|
||||
assert garmin_svc.get_remembered_email(user["id"]) == "current@example.com"
|
||||
|
||||
def test_falls_back_to_the_legacy_column_when_never_bound_since(self, db, user):
|
||||
db.execute(
|
||||
"UPDATE users SET garmin_email = ? WHERE id = ?",
|
||||
["legacy@example.com", user["id"]],
|
||||
)
|
||||
assert garmin_svc.get_remembered_email(user["id"]) == "legacy@example.com"
|
||||
|
||||
def test_disconnecting_drops_the_current_binding_but_not_the_legacy_value(
|
||||
self, db, user
|
||||
):
|
||||
db.execute(
|
||||
"UPDATE users SET garmin_email = ? WHERE id = ?",
|
||||
["legacy@example.com", user["id"]],
|
||||
)
|
||||
garmin_svc.save_token(user["id"], "tok", "current@example.com")
|
||||
garmin_svc.delete_token(user["id"])
|
||||
assert garmin_svc.get_remembered_email(user["id"]) == "legacy@example.com"
|
||||
|
||||
|
||||
class TestMfaHandling:
|
||||
def test_eof_from_the_mfa_prompt_becomes_an_actionable_error(
|
||||
self, db, user, monkeypatch
|
||||
|
||||
Reference in New Issue
Block a user