现象:网页触发同步报 "EOF when reading a line"。 原因:garth 的默认 MFA 提示是 input(),向 stdin 索取验证码。 gunicorn worker 没有 stdin,于是抛出 EOFError——错误信息本身 完全没提到 MFA,看不出该做什么。 方案:把"输验证码"和"日常同步"拆开。 - 新增 garmin_tokens 表存 garth 令牌(Client.dumps/loads 序列化) - garmin_login.py:在终端里跑一次,可正常输入验证码, 成功后令牌存库 - _connect() 优先加载令牌并 refresh_oauth2(),命中则完全跳过登录, 既不需要密码也不需要验证码(令牌有效期约一年) - 无令牌且密码登录撞上 MFA 时,抛 MFARequired 并给出具体该执行 哪条命令,而不是把 EOFError 原样抛给用户 接口: - GET /api/garmin/auth-status 返回是否已有令牌 - /api/garmin/sync 在已有令牌时不再强制要求密码 前端: - 有令牌时隐藏密码输入框,提示无需密码 - 同步返回 mfaRequired 时,展示需要在 NAS 上执行的具体命令 - 同步请求超时放宽到 180s(一周的天数 + 运动是多次上游调用) - 成功消息补上运动记录条数 tests (test_garmin_sync.py 新增 12 条,共 35): - 令牌存取、覆盖不累积、按用户隔离 - 有令牌时绝不调用 login() - MFA 的 EOFError 转成带操作指引的 MFARequired - 普通 401 不会被误标成 mfaRequired - 无令牌且无密码时给出明确拒绝 NAS 真机: 252 passed Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
53 lines
1.7 KiB
Python
53 lines
1.7 KiB
Python
"""Garmin routes: trigger a sync and read sync status."""
|
|
from flask import Blueprint, request, g, jsonify
|
|
|
|
from auth import require_auth
|
|
from db import query_one
|
|
from services import garmin as garmin_svc
|
|
|
|
bp = Blueprint("garmin", __name__)
|
|
|
|
|
|
@bp.route("/sync", methods=["POST"])
|
|
@require_auth
|
|
def sync():
|
|
data = request.get_json(silent=True) or {}
|
|
creds = {
|
|
"garminEmail": (data.get("garminEmail") or "").strip(),
|
|
"garminPassword": data.get("garminPassword") or "",
|
|
}
|
|
# Fall back to the stored Garmin email when only a password is supplied.
|
|
if not creds["garminEmail"]:
|
|
user = query_one("SELECT garmin_email FROM users WHERE id = ?", [g.user_id])
|
|
if user and user.get("garmin_email"):
|
|
creds["garminEmail"] = user["garmin_email"]
|
|
|
|
# With stored OAuth tokens no password is needed at all. Without them the
|
|
# plaintext password must come in the body, because only a hash is kept.
|
|
if not creds["garminPassword"] and not garmin_svc.has_token(g.user_id):
|
|
return (
|
|
jsonify({
|
|
"status": "error",
|
|
"recordsSynced": 0,
|
|
"message": "需要 Garmin 密码以执行同步,请在请求体中提供 garminPassword"
|
|
"(密码仅作哈希存储,无法还原)。",
|
|
}),
|
|
400,
|
|
)
|
|
|
|
result = garmin_svc.sync_data(g.user_id, creds)
|
|
return jsonify(result)
|
|
|
|
|
|
@bp.route("/auth-status", methods=["GET"])
|
|
@require_auth
|
|
def auth_status():
|
|
"""Whether a stored token exists, so the UI knows to ask for a password."""
|
|
return jsonify({"hasToken": garmin_svc.has_token(g.user_id)})
|
|
|
|
|
|
@bp.route("/status", methods=["GET"])
|
|
@require_auth
|
|
def status():
|
|
return jsonify(garmin_svc.get_sync_status(g.user_id))
|