fix(garmin): 两步验证账号同步报 EOFError,改用令牌登录

现象:网页触发同步报 "EOF when reading a line"。

原因:garth 的默认 MFA 提示是 input(),向 stdin 索取验证码。
gunicorn worker 没有 stdin,于是抛出 EOFError——错误信息本身
完全没提到 MFA,看不出该做什么。

方案:把"输验证码"和"日常同步"拆开。
- 新增 garmin_tokens 表存 garth 令牌(Client.dumps/loads 序列化)
- garmin_login.py:在终端里跑一次,可正常输入验证码,
  成功后令牌存库
- _connect() 优先加载令牌并 refresh_oauth2(),命中则完全跳过登录,
  既不需要密码也不需要验证码(令牌有效期约一年)
- 无令牌且密码登录撞上 MFA 时,抛 MFARequired 并给出具体该执行
  哪条命令,而不是把 EOFError 原样抛给用户

接口:
- GET /api/garmin/auth-status 返回是否已有令牌
- /api/garmin/sync 在已有令牌时不再强制要求密码

前端:
- 有令牌时隐藏密码输入框,提示无需密码
- 同步返回 mfaRequired 时,展示需要在 NAS 上执行的具体命令
- 同步请求超时放宽到 180s(一周的天数 + 运动是多次上游调用)
- 成功消息补上运动记录条数

tests (test_garmin_sync.py 新增 12 条,共 35):
- 令牌存取、覆盖不累积、按用户隔离
- 有令牌时绝不调用 login()
- MFA 的 EOFError 转成带操作指引的 MFARequired
- 普通 401 不会被误标成 mfaRequired
- 无令牌且无密码时给出明确拒绝

NAS 真机: 252 passed

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
ericwyuan
2026-08-23 19:57:40 +08:00
parent 6de7562cd8
commit af0604bce4
8 changed files with 410 additions and 38 deletions

View File

@@ -32,7 +32,10 @@ export interface SyncStatus {
export interface SyncResult {
status: 'success' | 'error';
recordsSynced: number;
activitiesSynced?: number;
message: string;
/** Set when the account has two-factor auth and no token is stored yet. */
mfaRequired?: boolean;
lastSyncTime: string;
}
@@ -164,17 +167,31 @@ class ApiClient {
// --- garmin ---
/**
* The backend stores only a hash of the Garmin password, so a live sync
* needs the plaintext password supplied here each time.
* With a stored OAuth token no password is needed. Without one, the
* plaintext password must be supplied because only a hash is kept — and an
* MFA-protected account cannot log in this way at all (see garmin_login.py).
*/
async syncGarminData(garminPassword: string, garminEmail?: string) {
const { data } = await this.client.post<SyncResult>('/garmin/sync', {
garminPassword,
...(garminEmail ? { garminEmail } : {}),
});
async syncGarminData(garminPassword?: string, garminEmail?: string) {
const { data } = await this.client.post<SyncResult>(
'/garmin/sync',
{
...(garminPassword ? { garminPassword } : {}),
...(garminEmail ? { garminEmail } : {}),
},
// Pulling a week of days plus activities is many upstream calls.
{ timeout: 180_000 }
);
return data;
}
/** Whether a stored Garmin token exists (then sync needs no password). */
async getGarminAuthStatus() {
const { data } = await this.client.get<{ hasToken: boolean }>(
'/garmin/auth-status'
);
return data.hasToken;
}
async getGarminSyncStatus() {
const { data } = await this.client.get<SyncStatus>('/garmin/status');
return data;