- 新增图像生成接口,支持试用、积分和自定义API Key模式 - 实现生成图片结果异步上传至MinIO存储,带重试机制 - 优化积分预扣除和异常退还逻辑,保障用户积分准确 - 添加获取生成历史记录接口,支持时间范围和分页 - 提供本地字典配置接口,支持模型、比例、提示模板和尺寸 - 实现图片批量上传接口,支持S3兼容对象存储 feat(admin): 增加管理员角色管理与权限分配接口 - 实现角色列表查询、角色创建、更新及删除功能 - 增加权限列表查询接口 - 实现用户角色分配接口,便于统一管理用户权限 - 增加系统字典增删查改接口,支持分类过滤和排序 - 权限控制全面覆盖管理接口,保证安全访问 feat(auth): 完善用户登录注册及权限相关接口与页面 - 实现手机号验证码发送及校验功能,保障注册安全 - 支持手机号注册、登录及退出接口,集成日志记录 - 增加修改密码功能,验证原密码后更新 - 提供动态导航菜单接口,基于权限展示不同菜单 - 实现管理界面路由及日志、角色、字典管理页面访问权限控制 - 添加系统日志查询接口,支持关键词和等级筛选 feat(app): 初始化Flask应用并配置蓝图与数据库 - 创建应用程序工厂,加载配置,初始化数据库和Redis客户端 - 注册认证、API及管理员蓝图,整合路由 - 根路由渲染主页模板 - 应用上下文中自动创建数据库表,保证运行环境准备完毕 feat(database): 提供数据库创建与迁移支持脚本 - 新增数据库创建脚本,支持自动检测是否已存在 - 添加数据库表初始化脚本,支持创建和删除所有表 - 实现RBAC权限初始化,包含基础权限和角色创建 - 新增字段手动修复脚本,添加用户API Key和积分字段 - 强制迁移脚本支持清理连接和修复表结构,初始化默认数据及角色分配 feat(config): 新增系统配置参数 - 配置数据库、Redis、Session和MinIO相关参数 - 添加AI接口地址及试用Key配置 - 集成阿里云短信服务配置及开发模式相关参数 feat(extensions): 初始化数据库、Redis和MinIO客户端 - 创建全局SQLAlchemy数据库实例和Redis客户端 - 配置基于boto3的MinIO兼容S3客户端 chore(logs): 添加示例系统日志文件 - 记录用户请求、验证码发送成功与失败的日志信息
101 lines
3.7 KiB
Python
101 lines
3.7 KiB
Python
from __future__ import annotations
|
|
|
|
import collections.abc as cabc
|
|
import typing as t
|
|
|
|
from .structures import CallbackDict
|
|
|
|
|
|
def csp_property(key: str) -> t.Any:
|
|
"""Return a new property object for a content security policy header.
|
|
Useful if you want to add support for a csp extension in a
|
|
subclass.
|
|
"""
|
|
return property(
|
|
lambda x: x._get_value(key),
|
|
lambda x, v: x._set_value(key, v),
|
|
lambda x: x._del_value(key),
|
|
f"accessor for {key!r}",
|
|
)
|
|
|
|
|
|
class ContentSecurityPolicy(CallbackDict[str, str]):
|
|
"""Subclass of a dict that stores values for a Content Security Policy
|
|
header. It has accessors for all the level 3 policies.
|
|
|
|
Because the csp directives in the HTTP header use dashes the
|
|
python descriptors use underscores for that.
|
|
|
|
To get a header of the :class:`ContentSecurityPolicy` object again
|
|
you can convert the object into a string or call the
|
|
:meth:`to_header` method. If you plan to subclass it and add your
|
|
own items have a look at the sourcecode for that class.
|
|
|
|
.. versionadded:: 1.0.0
|
|
Support for Content Security Policy headers was added.
|
|
|
|
"""
|
|
|
|
base_uri: str | None = csp_property("base-uri")
|
|
child_src: str | None = csp_property("child-src")
|
|
connect_src: str | None = csp_property("connect-src")
|
|
default_src: str | None = csp_property("default-src")
|
|
font_src: str | None = csp_property("font-src")
|
|
form_action: str | None = csp_property("form-action")
|
|
frame_ancestors: str | None = csp_property("frame-ancestors")
|
|
frame_src: str | None = csp_property("frame-src")
|
|
img_src: str | None = csp_property("img-src")
|
|
manifest_src: str | None = csp_property("manifest-src")
|
|
media_src: str | None = csp_property("media-src")
|
|
navigate_to: str | None = csp_property("navigate-to")
|
|
object_src: str | None = csp_property("object-src")
|
|
prefetch_src: str | None = csp_property("prefetch-src")
|
|
plugin_types: str | None = csp_property("plugin-types")
|
|
report_to: str | None = csp_property("report-to")
|
|
report_uri: str | None = csp_property("report-uri")
|
|
sandbox: str | None = csp_property("sandbox")
|
|
script_src: str | None = csp_property("script-src")
|
|
script_src_attr: str | None = csp_property("script-src-attr")
|
|
script_src_elem: str | None = csp_property("script-src-elem")
|
|
style_src: str | None = csp_property("style-src")
|
|
style_src_attr: str | None = csp_property("style-src-attr")
|
|
style_src_elem: str | None = csp_property("style-src-elem")
|
|
worker_src: str | None = csp_property("worker-src")
|
|
|
|
def __init__(
|
|
self,
|
|
values: cabc.Mapping[str, str] | cabc.Iterable[tuple[str, str]] | None = (),
|
|
on_update: cabc.Callable[[ContentSecurityPolicy], None] | None = None,
|
|
) -> None:
|
|
super().__init__(values, on_update)
|
|
self.provided = values is not None
|
|
|
|
def _get_value(self, key: str) -> str | None:
|
|
"""Used internally by the accessor properties."""
|
|
return self.get(key)
|
|
|
|
def _set_value(self, key: str, value: str | None) -> None:
|
|
"""Used internally by the accessor properties."""
|
|
if value is None:
|
|
self.pop(key, None)
|
|
else:
|
|
self[key] = value
|
|
|
|
def _del_value(self, key: str) -> None:
|
|
"""Used internally by the accessor properties."""
|
|
if key in self:
|
|
del self[key]
|
|
|
|
def to_header(self) -> str:
|
|
"""Convert the stored values into a cache control header."""
|
|
from ..http import dump_csp_header
|
|
|
|
return dump_csp_header(self)
|
|
|
|
def __str__(self) -> str:
|
|
return self.to_header()
|
|
|
|
def __repr__(self) -> str:
|
|
kv_str = " ".join(f"{k}={v!r}" for k, v in sorted(self.items()))
|
|
return f"<{type(self).__name__} {kv_str}>"
|