Harden auth with revocable sessions, cookies, and single-login default.

Issue short-lived access JWTs backed by AuthSession rows, HttpOnly cookies with refresh rotation, idle timeout, session management UI, WebCRT ownership caps, and optional Redis login rate limits; new logins revoke other sessions by default.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-06 14:13:37 +08:00
parent ba33ab5c4f
commit 20c2fcd496
34 changed files with 1462 additions and 149 deletions

View file

@ -61,6 +61,7 @@ const en = {
logs: "Audit logs",
users: "User admin",
apiKeys: "API keys",
sessions: "Sessions",
},
announce: {
a1: "Dark workbench shell is live — other modules follow the same palette.",
@ -97,6 +98,8 @@ const en = {
auditDesc: "Live task overview and operation logs",
apiKeys: "API Keys",
apiKeysDesc: "Issue MCP/script tokens per user with expiry",
sessions: "Login sessions",
sessionsDesc: "Review and revoke logins on other devices",
},
},
network: {
@ -519,6 +522,7 @@ const en = {
titleUsers: "Users",
titleAudit: "Audit",
titleApiKeys: "API Keys",
titleSessions: "Login sessions",
navUme: "UME",
netxApi: "netx api",
oclawBridge: "oclaw WSS",
@ -538,6 +542,18 @@ const en = {
loggingIn: "Signing in…",
loginFailed: "Login failed",
logout: "Sign out",
sessionsTitle: "Login sessions",
sessionsHint: "Manage browser/device logins for this account. Revoked sessions must sign in again.",
sessionsEmpty: "No active sessions.",
revokeOtherSessions: "Revoke other sessions",
revokeSession: "Revoke",
sessionCurrent: "Current",
sessionRevoked: "Session revoked",
sessionsRevokedOthers: "Revoked {{count}} other session(s)",
revokeCurrentConfirm: "This is your current session; revoking it requires signing in again. Continue?",
colSession: "Session",
colLastSeen: "Last seen",
colCreated: "Created",
usersTitle: "User management",
usersHint: "Only admins can create and manage local accounts.",
addUser: "Add user",
@ -614,7 +630,7 @@ const en = {
confirmPassword: "Confirm new password",
savePassword: "Save new password",
savingPassword: "Saving…",
passwordTooShort: "New password must be at least 6 characters",
passwordTooShort: "New password must be at least 8 characters",
passwordMismatch: "New passwords do not match",
passwordMustChange: "New password must differ from the default/old password",
},

View file

@ -61,6 +61,7 @@ const zh = {
logs: "操作日志",
users: "用户管理",
apiKeys: "API Key",
sessions: "登录会话",
},
announce: {
a1: "深色工作台已上线,其它模块将沿用同一套深色体系。",
@ -97,6 +98,8 @@ const zh = {
auditDesc: "任务概览与操作日志",
apiKeys: "API Key",
apiKeysDesc: "为用户生成 MCP/脚本用 Token,可设有效期",
sessions: "登录会话",
sessionsDesc: "查看并踢掉其他设备上的登录",
},
},
network: {
@ -515,6 +518,7 @@ const zh = {
titleUsers: "用户管理",
titleAudit: "操作审计",
titleApiKeys: "API Key",
titleSessions: "登录会话",
navUme: "UME 对接",
netxApi: "netx api",
oclawBridge: "oclaw WSS",
@ -534,6 +538,18 @@ const zh = {
loggingIn: "登录中…",
loginFailed: "登录失败",
logout: "退出",
sessionsTitle: "登录会话",
sessionsHint: "管理当前账号在各浏览器/设备上的登录。踢掉会话后对方需重新登录。",
sessionsEmpty: "当前没有活跃会话。",
revokeOtherSessions: "踢掉其他会话",
revokeSession: "踢掉",
sessionCurrent: "当前",
sessionRevoked: "会话已吊销",
sessionsRevokedOthers: "已踢掉 {{count}} 个其他会话",
revokeCurrentConfirm: "这是当前会话,踢掉后需要重新登录。继续?",
colSession: "会话",
colLastSeen: "最近活动",
colCreated: "创建时间",
usersTitle: "用户管理",
usersHint: "仅管理员可创建与管理本地账号。",
addUser: "添加用户",
@ -609,7 +625,7 @@ const zh = {
confirmPassword: "确认新密码",
savePassword: "保存新密码",
savingPassword: "保存中…",
passwordTooShort: "新密码至少 6 位",
passwordTooShort: "新密码至少 8 位",
passwordMismatch: "两次输入的新密码不一致",
passwordMustChange: "新密码不能与默认/旧密码相同",
},