Require browser login for scheduled-task HTTP APIs.

List/run/pause/resume/delete now return 401 without UDS cookies; hide sidebar chrome when logged out. uds-auth still validates the session store on the same routes.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-08 08:06:54 +08:00
parent 67238d746e
commit a38f3dcec3
4 changed files with 122 additions and 17 deletions

View file

@ -160,6 +160,21 @@ window.__ModuleLoader__.load({
const NS = 'dsh-ops-cron'
const inject = ['slots', 'locale', 'settingsScope']
const API = '/dsh-ops-cron'
function readCookie(name) {
const parts = String(document.cookie || '').split(';')
for (const part of parts) {
const idx = part.indexOf('=')
if (idx < 0) continue
if (part.slice(0, idx).trim() !== name) continue
try { return decodeURIComponent(part.slice(idx + 1).trim()) } catch { return part.slice(idx + 1).trim() }
}
return null
}
function hasUdsLoginCookie() {
return !!(readCookie('PORTALSSOUser') || readCookie('ZTEDPGSSOUser') || readCookie('UDS_FALLBACK_USER'))
}
const LOCALE_NS = 'settings.dshCronTasks'
const TITLE_PREFIX = '定时任务 · '
const listSnapshot = {
@ -518,6 +533,9 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
}
async function api(path, options = {}) {
if (!hasUdsLoginCookie() && path !== '/health') {
throw new Error('登录后才能使用定时任务')
}
const response = await fetch(`${API}${path}`, {
...options,
headers: { accept: 'application/json', ...(options.body ? { 'content-type': 'application/json' } : {}), ...options.headers },
@ -1525,6 +1543,15 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
const place = () => {
const found = findNewSessionButton()
if (!found) return
if (!hasUdsLoginCookie()) {
if (entry && entry.isConnected) entry.remove()
if (listRoot && listRoot.isConnected) listRoot.remove()
if (cronOn) {
cronOn = false
setCronMode(findSidebarRoot(found), false, entry, t)
}
return
}
const sidebar = findSidebarRoot(found)
const region = findRegionArea(sidebar)
let anchor = found
@ -1612,6 +1639,9 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
}
place()
const onAuth = () => { place() }
window.addEventListener('focus', onAuth)
window.addEventListener('uds-auth-changed', onAuth)
let boots = 0
const boot = () => {
boots += 1
@ -1621,6 +1651,8 @@ body>.dsh-ct-main{position:fixed;top:0;right:0;bottom:0;left:var(--dsh-ct-sideba
requestAnimationFrame(boot)
const timer = setInterval(place, 4000)
return () => {
window.removeEventListener('focus', onAuth)
window.removeEventListener('uds-auth-changed', onAuth)
observer.disconnect()
clearInterval(timer)
if (placeRaf) cancelAnimationFrame(placeRaf)