Tra
b9ff408bdd
fix: UC subdirectory listing fails due to missing stoken parameter
...
When the frontend requests subdirectory contents for UC drive shares, the
stoken query parameter is mishandled in two places, breaking directory browsing:
1. URLParamUtil.handleTruncatedUrl() does not exclude stoken from the URL
construction loop. As a result, the stoken value gets appended to the share
URL (e.g. https://drive.uc.cn/s/xxx?stoken=yyy ). The extra query string
breaks the UC URL regex match in PanDomainTemplate, causing the parser to
fall back to the default IPanTool.parseFileList() which returns
"Not implemented yet".
2. ParserApi.getFileList() does not accept stoken as a method parameter and
does not forward it to ShareLinkInfo.otherParam. Even when the stoken is
present in the request URL, UcTool.parseFileList() cannot find it and must
re-authenticate against the UC API — which fails without proper auth cookies.
The fix:
- URLParamUtil: add stoken to the param exclusion list
- ParserApi: add String stoken parameter and put it into otherParam
Both first-level and nested directory listing work correctly after this fix.
2026-07-24 18:04:52 +08:00
qaiu
aeb4394cf8
fix GHSA-997r-7xx2-p9x6
2026-07-22 10:25:10 +08:00
q
b70e30796f
ci: package fuller jre for native builds
dependabot/npm_and_yarn/web-front/npm_and_yarn-c42958dede
v0.4.1
2026-07-19 09:57:31 +08:00
q
d3ef521773
fix: support donated auth for 123 directory downloads
v0.4.0
2026-07-19 09:39:55 +08:00
q
2969c92d3d
build jre
2026-07-19 02:06:33 +08:00
q
2fde421169
chore: bump version to 0.3.9
v0.3.9
2026-07-19 01:11:57 +08:00
q
3494271150
chore: bump version to 0.3.8
v0.3.8
2026-07-19 00:55:54 +08:00
q
675d930f86
fix: 123网盘捐赠账号无需临时auth参数即可自动生效,修复token前缀与脏数据问题
...
- 前端: getCurrentPanType() 补全123网盘域名匹配正则(share.123pan.cn等子域名)
- 前端: 临时认证弹窗补充123云盘(YE)选项及提示文案
- 前端: submitDonateAccount() 按当前authType只提交相关字段,避免切换认证方式后
残留的用户名/密码脏数据被一并提交
- 后端: URLParamUtil.addParam() 不再无条件用静态yml配置覆盖已生效的临时认证/
自动捐赠账号回退(增加 __TEMP_AUTH_ADDED 判断)
- 后端: CacheServiceImpl 新增 applyDonatedAccountFallback(),请求未带auth参数
且无静态配置时自动从捐赠账号池随机取一个可用账号使用,并在解析失败时记录/
自动禁用失败账号
- 后端: DbServiceImpl.getRandomDonatedAccount() 对非password类型账号强制丢弃
历史遗留的username/password字段,避免被误当账号密码登录
- 解析器: Ye2Tool 清理token/authorization前缀中的"Bearer ",避免拼接成
'Bearer Bearer xxx' 导致123接口返回 tokenstring should not contain bearer
已通过本地实测验证: 捐赠123账号后,不带auth参数直接请求
/json/parser?url=https://1815268665.share.123pan.cn/123pan/iaKtVv-r4aCd
可正常返回200及直链
2026-07-18 23:21:56 +08:00
q
5e20ed5050
fix: 123网盘(YE)支持authorization别名配置并修复auth临时参数登录被覆盖问题, 更新README认证说明, bump version to 0.3.7
...
引用 #201 #198 #116
说明: 123解析仅限于本地部署(可Windows一键运行 run.bat),公共/云端服务因风控限制不保证可用
v0.3.7
2026-07-18 12:28:00 +08:00
qaiu
91f4fcaa76
更新 README.md
...
oosmetrics不可用
2026-07-11 06:28:53 +08:00
qaiu
0754fe20f1
更新 README.md
2026-07-10 16:41:58 +08:00
qaiu
034fd20d3b
更新 README.md
2026-07-10 16:41:06 +08:00
q
24bf98bca9
fix: support 123pan redirected share links
dependabot/maven/maven-6421fd6730
2026-07-06 08:50:18 +08:00
qaiu
275f6b9e6d
更新 README.md
2026-06-23 17:10:09 +08:00
qaiu
5db9e422f4
更新 README.md
2026-06-11 12:03:44 +08:00
qaiu
705b6ba4b7
Merge pull request #195 from yukaidi1220/codex/full-main-clean
...
Clean up fork changes for upstream review
v0.3.6
2026-06-10 21:32:21 +08:00
yukaidi
0edc057347
docs: update parser and custom script docs
2026-06-10 21:23:05 +08:00
yukaidi
6ae5d998e6
fix(frontend): improve directory and timestamp display
2026-06-10 21:22:29 +08:00
yukaidi
cbb442ceb6
fix(web): harden cache and API services
2026-06-10 21:21:52 +08:00
yukaidi
0103841fb5
fix(parser): harden built-in pan parsers
2026-06-10 21:20:40 +08:00
yukaidi
b6b7f0d8b7
fix(parser): harden runtime resource handling
2026-06-10 21:19:56 +08:00
yukaidi
46c6827eda
fix(core): harden proxy and routing lifecycle
2026-06-10 21:19:18 +08:00
yukaidi
1ef6e120a8
ci: improve build and packaging workflow
2026-06-10 21:18:44 +08:00
qaiu
65d518373d
Merge pull request #191 from yukaidi1220/lecloud-direct-download
...
feat: 乐云 directDownload 接口支持 & 缓存配置补充完善
2026-06-05 23:02:18 +08:00
yukaidi
bca4da4b6c
feat: 乐云 directDownload 接口支持 & 缓存配置补充完善
...
- 新增 directDownload (GET) 接口,比 packageDownloadWithFileIds 少一次请求
- 每次随机选择下载方式,失败自动 fallback 到另一种
- 统一所有下载方法的 Promise 参数传递
- 添加 HTTP 状态码日志便于调试
- 优化 app-dev.yml 缓存配置注释,补充所有缺失的网盘类型
2026-06-05 22:48:01 +08:00
qaiu
0fd78defcb
feat(ct): 升级城通网盘接口并实现目录分享解析
...
- 移除token参数,新增url参数至API1请求
- API2新增start_time/wait_seconds/verifycode/share_id/acheck=1参数
- parse()中从API1响应提取FileInfo(file_name/file_id/file_size/file_time/username)
- 新增parseFileList()实现目录分享解析,通过getdir.php+file_list API获取文件列表
- 新增CTD枚举项匹配城通网盘目录分享链接(/d/路径)
2026-06-03 09:46:16 +00:00
qaiu
452fd0ea2c
Merge pull request #190 from yukaidi1220/pr/native-package
...
CI: 新增原生环境打包 & 启动日志改进
v3.0.4
2026-05-31 17:02:50 +08:00
yukaidi
dd8f2efb37
ci: Release 自动生成更新说明(generate_release_notes)
2026-05-31 16:39:23 +08:00
yukaidi
0feb8e798a
fix: PR#190 review 修复 — 配置查找顺序/页面日志/ZIP结构/注释
...
- 配置文件查找顺序与 Deploy 保持一致(先当前目录,再 resources/)
- 页面地址日志改用 onComplete,无论演练场加载成功失败均输出
- Windows ZIP 移除 /* 通配符,与 Linux 保持一致的顶层目录结构
- 修正注释:同步读文件会阻塞 event loop,不再声称'避免阻塞'
- YAML 正则和 jdeps 回退列表补充适用范围说明
2026-05-31 16:34:19 +08:00
yukaidi
d55d8edd2f
AppMain: 启动日志增加前端页面访问地址提示
2026-05-31 14:00:45 +08:00
yukaidi
451496f102
CI: 新增 Linux/Windows 原生环境打包 (jlink + 精简 JRE) 及 Docker 多平台构建
2026-05-31 14:00:45 +08:00
qaiu
6d6351bd58
更新 README.md
2026-05-31 07:02:09 +08:00
q
1a5fc8d1ef
feat: truncate long error msg, fix lanzou folder regex, bump version to 0.3.4
v0.3.4
2026-05-30 01:16:17 +08:00
qaiu
a44f30f7e5
Merge pull request #189 from qaiu/copilot/update-readme-badge
...
Update README maven badge to track tag-triggered workflow status
2026-05-30 00:17:51 +08:00
copilot-swe-agent[bot]
f9ebd34de3
docs: remove branch filter from maven workflow badge
2026-05-29 16:16:43 +00:00
copilot-swe-agent[bot]
b47db300a6
Initial plan
2026-05-29 16:10:44 +00:00
qaiu
d19d8573f9
Merge pull request #188 from yukaidi1220/fix/qqwtool-json-api
...
fix(QQwTool): 改用 POST JSON API 解析 QQ 邮箱云盘链接
2026-05-29 23:54:20 +08:00
qaiu
799e120069
Merge pull request #187 from yukaidi1220/feat/contributions
...
安全加固、新功能、Bug 修复与代码质量改进
2026-05-29 23:53:09 +08:00
yukaidi
13f83e8795
fix(QQwTool): 改用 POST JSON API 解析 QQ 邮箱云盘链接
...
旧实现通过 GET 请求获取 HTML 并正则提取 JS 变量,但接口已改为返回 JSON,
导致 NumberFormatException。改为 POST 请求 `https://wx.mail.qq.com/s `,
body 为 `f=json&k={shareKey}`,解析 JSON 响应中的 body.url/name/size。
- 使用 postAbs() 替代 request() 以正确处理 HTTPS
- 使用 asJson() 兼容 gzip 响应
- 使用 complete() 正确存储 downloadUrl
- 添加 User-Agent、URL 编码 shareKey
2026-05-29 22:26:44 +08:00
yukaidi
7b5900aae4
refactor: 代码质量清理与日志规范化
...
- 替换 System.out.println/printStackTrace 为 Logger: MkgsTool, PodTool, WsTool, IpExtractor, ReqIpUtil, LogStatistics
- JsPlaygroundLogger 日志列表限制最大 1000 条防止内存泄漏
- JsScriptLoader JarFile 改用 try-with-resources 防止文件句柄泄漏
- DbServiceImpl Thread.sleep 改为 vertx.setTimer 避免阻塞 event loop
- 删除未使用的 api.js,删除空的 ParserApiClientLinkTest
- 移除前端未使用的导入和死代码 (downloaderService, monacoTypes)
- 提取 previewBaseUrl 到 constants.js 常量文件
2026-05-29 14:23:26 +08:00
yukaidi
e36c0bbe45
fix: Docker 部署优化
...
- run.sh 改用 exec 直接运行 Java,修复 Docker 中 ShutdownHook 失效
- Dockerfile 预创建 db 和 logs 目录,添加非 root 用户运行
- Docker entrypoint 以 root 运行再降权,解决 volume 权限问题
- EXPOSE 改为仅 6401,entrypoint 添加 -Duser.timezone
2026-05-29 14:23:01 +08:00
yukaidi
af723aed3a
fix: NPE 修复、资源泄漏修复及其他 Bug 修复
...
- 修复 12 处 NPE 风险: FjTool/FsTool/IzTool/LzTool/MkwTool/P115Tool/PdbTool/QQTool/ParserCreate/CommonUtils/ShareLinkInfo/URLParamUtil
- 修复 4 处 Vert.x 资源泄漏: 测试类中 Vertx 实例未关闭
- 修复 CacheManager 防重入和 registerPeriodicCleanup 就绪检查
- 修复 ParserApi 中 redirectUrl()/viewUrl() Promise 未 complete
- 修复 CacheManager.updateTotalByField Promise 永不完成
- 修复 AppMain ShutdownHook 注册,确保 Vert.x 先于 JDBCPoolInit 关闭
- 修复 RouterHandlerFactory failureHandler 恢复返回 failure message
- 修复 ParserCreate/LzTool 收窄 catch 异常类型
- 修复 IzTool/FjTool/IzToolWithAuth 并发安全 (volatile + header 副本)
- 修复 P115Tool UA 为 null 时的 NPE,添加默认 User-Agent
- Font Awesome CDN 换源为 s4.zstatic.net,避免 bootcdn 投毒风险
- DirectoryTree selectAll 补 parserUrl 检查,Home 组件名 App→Home
2026-05-29 14:22:40 +08:00
yukaidi
0978186679
feat: 新功能与配置优化
...
- QQscTool: 支持多文件和目录解析,通过 GetFileList API 实现递归目录导航
- Home: 从粘贴文本中自动提取分享链接
- DirectoryTree: 目录浏览添加复制直链按钮
- domainName 改为可选,未配置时自动从请求地址推断
- 统一版本号管理,GitHub URL 构建时自动从 git remote origin 识别
- vue.config.js 添加前端构建配置,sync-version.js 构建时同步版本号
2026-05-29 14:21:32 +08:00
yukaidi
17460ff271
fix(security): 安全漏洞修复与依赖升级
...
- 升级 Vert.x 4.5.24 → 4.5.27, postgresql 42.7.3 → 42.7.11, logback 1.5.18 → 1.5.32, axios 1.13.5 → 1.16.1
- 修复 JWT 签名验证和密码比较的时序攻击漏洞 (MessageDigest.isEqual)
- 修复 AESUtils 使用不安全 Random 改为 SecureRandom
- 修复登录用户枚举和异常信息泄露,统一错误提示
- 修复 RateLimiter count++ 非原子操作 (AtomicInteger)
- 修复 JsParserExecutor DCL 模式缺少 volatile
- 修复 Token 日志泄露,仅打印前8字符
- 修复 Playground 密码时序攻击和堆栈泄露
- 所有 window.open 添加 noopener,noreferrer
- LocalConstant 改用 ConcurrentHashMap 保证线程安全
- Dockerfile 添加非 root 用户运行,secret.yml 加入 .gitignore
2026-05-29 14:20:54 +08:00
yukaidi
f81b3852ee
fix: Font Awesome CDN 换源为 s4.zstatic.net,避免 bootcdn 投毒风险
2026-05-29 14:10:06 +08:00
yukaidi
37abebf8f8
fix(QQscTool): 简化 filesetId 正则,避免反斜杠转义问题
2026-05-29 13:58:13 +08:00
yukaidi
79fab8c0d6
fix: 修复前端错误信息丢失 & QQscTool filesetId 提取失败
...
- 前端 axios 对 HTTP 非2xx直接reject,catch块丢失后端错误信息,从 error.response.data.msg 提取实际错误展示给用户
- QQscTool extractFilesetId 正则未适配 Nuxt 转义JSON格式
2026-05-29 13:46:25 +08:00
yukaidi
9b70fb2778
feat(QQscTool): 支持多文件和目录解析,通过 GetFileList API 实现递归目录导航
2026-05-29 13:22:12 +08:00
yukaidi
bd2868748f
feat(Home): 从粘贴文本中自动提取分享链接
2026-05-29 13:08:22 +08:00
yukaidi
1f47bf13b5
fix(QQscTool): 检测被和谐文件,避免返回无效直链
2026-05-29 12:56:28 +08:00