Compare commits

..

2 Commits

Author SHA1 Message Date
copilot-swe-agent[bot]
24025e0ae6 Remove unused user system residual code (SysUser, UserService, UserServiceImpl, JwtUtil)
Agent-Logs-Url: https://github.com/qaiu/netdisk-fast-download/sessions/1ce8d72f-79b3-4be4-b9a3-4cab8bbe7b19

Co-authored-by: qaiu <29825328+qaiu@users.noreply.github.com>
2026-04-11 01:37:21 +00:00
copilot-swe-agent[bot]
d8bffc19ce Initial plan 2026-04-11 01:35:41 +00:00
8 changed files with 38 additions and 1220 deletions

View File

@@ -1,15 +1,3 @@
# 一款网盘分享链接云解析快速下载服务
QQ交流群1017480890
<p align="center">
<a href="https://github.com/qaiu/netdisk-fast-download/actions/workflows/maven.yml"><img src="https://img.shields.io/github/actions/workflow/status/qaiu/netdisk-fast-download/maven.yml?branch=v0.1.9b8a&style=flat"></a>
<a href="https://www.oracle.com/cn/java/technologies/downloads"><img src="https://img.shields.io/badge/jdk-%3E%3D17-blue"></a>
<a href="https://vertx-china.github.io"><img src="https://img.shields.io/badge/vert.x-4.5.22-blue?style=flat"></a>
<a href="https://raw.githubusercontent.com/qaiu/netdisk-fast-download/master/LICENSE"><img src="https://img.shields.io/github/license/qaiu/netdisk-fast-download?style=flat"></a>
<a href="https://github.com/qaiu/netdisk-fast-download/releases/"><img src="https://img.shields.io/github/v/release/qaiu/netdisk-fast-download?style=flat"></a>
<p align="center">
<a href="https://trendshift.io/repositories/12101" target="_blank"><img src="https://trendshift.io/api/badge/repositories/12101" alt="qaiu%2Fnetdisk-fast-download | Trendshift" style="width: 250px; height: 55px;" width="250" height="55"/></a>
</p>
<div align="center" style="display:flex; justify-content:center; gap:10px; align-items:flex-start;">
<img
src="https://github.com/user-attachments/assets/bf266d0a-aaf8-4772-9231-e38a4b7bb6cb"
@@ -22,14 +10,21 @@ QQ交流群1017480890
style="width:300px; max-width:300px; flex:none;"
>
</div>
<p align="center">
<a href="https://trendshift.io/repositories/12101" target="_blank"><img src="https://trendshift.io/api/badge/repositories/12101" alt="qaiu%2Fnetdisk-fast-download | Trendshift" style="width: 250px; height: 55px;" width="250" height="55"/></a>
</p>
> netdisk-fast-download网盘直链解析可以把云盘分享链接转为直链可广泛应用于各类下载站资源站个人博客图床APP下载更新视频点播等领域。支持市面各大主流云盘的文件分享以及文件夹分享链接已支持蓝奏云/蓝奏云优享/奶牛快传/移动云云空间/小飞机盘/亿方云/123云盘/Cloudreve等支持加密分享以及部分网盘文件夹分享。
<p align="center">
<a href="https://github.com/qaiu/netdisk-fast-download/actions/workflows/maven.yml"><img src="https://img.shields.io/github/actions/workflow/status/qaiu/netdisk-fast-download/maven.yml?branch=v0.1.9b8a&style=flat"></a>
<a href="https://www.oracle.com/cn/java/technologies/downloads"><img src="https://img.shields.io/badge/jdk-%3E%3D17-blue"></a>
<a href="https://vertx-china.github.io"><img src="https://img.shields.io/badge/vert.x-4.5.22-blue?style=flat"></a>
<a href="https://raw.githubusercontent.com/qaiu/netdisk-fast-download/master/LICENSE"><img src="https://img.shields.io/github/license/qaiu/netdisk-fast-download?style=flat"></a>
<a href="https://github.com/qaiu/netdisk-fast-download/releases/"><img src="https://img.shields.io/github/v/release/qaiu/netdisk-fast-download?style=flat"></a>
[官方文档](https://nfd-parser.github.io/)
[API接入](https://nfdparser.apifox.cn/)
[公益解析lz站](https://lz.qaiu.top)
[公益解析lz0站](https://lz0.qaiu.top)
[专业版189站注册体验](https://189.qaiu.top)
# netdisk-fast-download 网盘分享链接云解析服务
QQ交流群1017480890
netdisk-fast-download网盘直链云解析(nfd云解析)能把网盘分享下载链接转化为直链,支持多款云盘,已支持蓝奏云/蓝奏云优享/奶牛快传/移动云云空间/小飞机盘/亿方云/123云盘/Cloudreve等支持加密分享以及部分网盘文件夹分享。
## 快速开始
命令行下载分享文件:
@@ -55,10 +50,15 @@ https://nfd-parser.github.io/nfd-preview/preview.html?src=https%3A%2F%2Flz.qaiu.
**Playground功能** [JS解析器演练场密码保护说明](web-service/doc/PLAYGROUND_PASSWORD_PROTECTION.md)
## 体验地址
[公益解析1](https://lz.qaiu.top)
[公益解析2](https://lz0.qaiu.top)
[大文件解析专属版,限时开放,注册体验](https://189.qaiu.top)
**注意⚠小飞机解析有IP限制多数云服务商的大陆IP会被拦截可以自行配置代理和本程序无关**
**注意⚠️收到很多用户反馈,小飞机近期封号频繁,请尽可能选择其他网盘分享**
**注意⚠️请不要过度依赖 lz.qaiu.top建议本地搭建或者云服务器自行搭建。请求量过多的话服务器可能会被云盘厂商限制遇到解析失败的分享链接不要着急提issues请先检查分享是否有效** [lz站](https://lz.qaiu.top) 和 [lz0](https://lz0.qaiu.top) 不支持大文件,请使用 [189站](https://189.qaiu.top) 注册体验。
main分支依赖JDK17, 提供了JDK11分支[main-jdk11](https://github.com/qaiu/netdisk-fast-download/tree/main-jdk11)
**0.1.8及以上版本json接口格式有调整 参考json返回数据格式示例**
**小飞机解析有IP限制多数云服务商的大陆IP会被拦截可以自行配置代理和本程序无关**
**注意: 请不要过度依赖lz.qaiu.top预览地址服务建议本地搭建或者云服务器自行搭建。解析次数过多IP会被部分网盘厂商限制不推荐做公共解析。**
## 网盘支持情况:
> 20230905 奶牛云直链做了防盗链需加入请求头Referer: https://cowtransfer.com/

View File

@@ -68,8 +68,8 @@ public enum PanDomainTemplate {
t-is.cn
*/
LZ("蓝奏云",
compile("https://(?:[a-zA-Z\\d-]+\\.)?(?:" +
"(?:lanzoul|" +
compile("https://(?:[a-zA-Z\\d-]+\\.)?(" +
"lanzoul|" +
"lanzouh|" +
"lanosso|" +
"lanpv|" +
@@ -95,16 +95,14 @@ public enum PanDomainTemplate {
"lanzv|" +
"dmpdmp|" +
"lanrar|" +
"webgetstore|" +
"lanzb|" +
"lanzoux|" +
"lanzout|" +
"lanzouc|" +
"lanzoui|" +
"lanzoug|" +
"lanzoum)\\.com" +
"|t-is\\.cn" +
")/(?<KEY>.+)"),
"lanzoum" +
")\\.com/(?<KEY>.+)"),
"https://w1.lanzn.com/{shareKey}",
LzTool.class),
@@ -117,7 +115,7 @@ public enum PanDomainTemplate {
// https://lecloud.lenovo.com/share/
LE("联想乐云",
compile("https://lecloud\\.lenovo\\.com/share/(?<KEY>.+)"),
compile("https://lecloud?\\.lenovo\\.com/share/(?<KEY>.+)"),
"https://lecloud.lenovo.com/share/{shareKey}",
LeTool.class),
@@ -243,7 +241,7 @@ public enum PanDomainTemplate {
EcTool.class),
// https://cowtransfer.com/s/
COW("奶牛快传",
compile("https://(?:[a-zA-Z\\d-]+\\.)?cowtransfer\\.com/s/(?<KEY>.+)"),
compile("https://(.*)cowtransfer\\.com/s/(?<KEY>.+)"),
"https://cowtransfer.com/s/{shareKey}",
CowTool.class),
CT("城通网盘",
@@ -266,7 +264,7 @@ public enum PanDomainTemplate {
PodTool.class),
// 404网盘 https://drive.google.com/file/d/xxx/view?usp=sharing
PGD("GoogleDrive",
compile("https://(?:[a-zA-Z\\d-]+\\.)?drive\\.google\\.com/file/d/(?<KEY>.+)/view(\\?usp=(sharing|drive_link))?"),
compile("https://drive\\.google\\.com/file/d/(?<KEY>.+)/view(\\?usp=(sharing|drive_link))?"),
"https://drive.google.com/file/d/{shareKey}/view?usp=sharing",
PgdTool.class),
// iCloud https://www.icloud.com.cn/iclouddrive/xxx#fonts
@@ -276,11 +274,11 @@ public enum PanDomainTemplate {
PicTool.class),
// https://www.dropbox.com/scl/fi/cwnbms1yn8u6rcatzyta7/emqx-5.0.26-el7-amd64.tar.gz?rlkey=3uoi4bxz5mv93jmlaws0nlol1&e=8&st=fe0lclc2&dl=0
PDB("dropbox",
compile("https://www\\.dropbox\\.com/scl/fi/(?<KEY>\\w+)/.+?rlkey=(?<PWD>\\w+).*"),
compile("https://www.dropbox.com/scl/fi/(?<KEY>\\w+)/.+?rlkey=(?<PWD>\\w+).*"),
"https://www.dropbox.com/scl/fi/{shareKey}/?rlkey={pwd}&dl=0",
PdbTool.class),
P115("115网盘",
compile("https://(115|anxia)\\.com/s/(?<KEY>\\w+)(\\?password=(?<PWD>\\w+))?([&#].*)?"),
compile("https://(115|anxia).com/s/(?<KEY>\\w+)(\\?password=(?<PWD>\\w+))?([&#].*)?"),
"https://115.com/s/{shareKey}?password={pwd}",
P115Tool.class),
// 链接https://www.yunpan.com/surl_yD7wz4VgU9v提取码fc70
@@ -321,7 +319,7 @@ public enum PanDomainTemplate {
MnesTool.class),
// https://music.163.com/#/song?id=xxx
MNE("网易云音乐歌曲详情",
compile("https://(y\\.)?music\\.163\\.com/(?:#/|m/)?song\\?id=(?<KEY>.+)(&.*)?"),
compile("https://(y.)?music\\.163\\.com/(#|m/)?song\\?id=(?<KEY>.+)(&.*)?"),
"https://music.163.com/#/song?id={shareKey}",
MnesTool.MneTool.class),
// https://c6.y.qq.com/base/fcgi-bin/u?__=xxx
@@ -342,7 +340,7 @@ public enum PanDomainTemplate {
MkgsTool.class),
// https://www.kugou.com/share/2bi8Fe9CSV3.html?id=2bi8Fe9CSV3#6ed9gna4"
MKGS2("酷狗音乐分享2",
compile("https://(?:[a-zA-Z\\d-]+\\.)?kugou\\.com/share/(?<KEY>.+)\\.html.*"),
compile("https://(?:[a-zA-Z\\d-]+\\.)?kugou\\.com/share/(?<KEY>.+).html.*"),
"https://www.kugou.com/share/{shareKey}.html",
MkgsTool.Mkgs2Tool.class),
// https://www.kugou.com/mixsong/2bi8Fe9CSV3

View File

@@ -1,355 +0,0 @@
#!/usr/bin/env python3
"""
飞书公开分享 直链解析 + 批量下载 (aria2/Motrix)
支持: 单文件链接 / 文件夹链接(递归子目录)
用法:
python feishu_dl.py <链接> # 推送到 Motrix
python feishu_dl.py <链接> -d D:/Downloads # 指定下载目录
python feishu_dl.py <链接> --list # 仅列出文件,不下载
python feishu_dl.py <链接> --aria2c # 输出 aria2c 命令行
"""
import sys, os, re, json, uuid, ssl, gzip, argparse
import http.cookiejar
import urllib.request, urllib.error
from urllib.parse import unquote, quote
# ─── Motrix aria2 RPC 默认配置 ──────────────────────────
ARIA2_RPC_URL = "http://localhost:16800/jsonrpc"
ARIA2_SECRET = "motrix"
# ────────────────────────────────────────────────────────
UA = ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 "
"(KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36")
# 飞书 obj_type 映射 (type=12 上传文件可下载, type=0 文件夹可递归)
OBJ_TYPES = {
0: "📁 文件夹", 2: "📝 旧版文档", 3: "📊 表格", 8: "🧠 思维导图",
11: "📽 幻灯片", 12: "📄 文件", 22: "📝 新版文档", 30: "📋 画板",
44: "📊 多维表格", 84: "📑 知识库", 123: "❓ 未知", 124: "❓ 未知",
}
# v3 列表 API 支持的 obj_type
LIST_OBJ_TYPES = [0, 2, 22, 44, 3, 30, 8, 11, 12, 84, 123, 124]
# ─── 网络工具 ────────────────────────────────────────────
def _ctx():
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
return ctx
def make_opener(jar):
return urllib.request.build_opener(
urllib.request.HTTPSHandler(context=_ctx()),
urllib.request.HTTPCookieProcessor(jar),
)
def decode_body(resp):
data = resp.read()
if resp.headers.get("Content-Encoding") == "gzip":
data = gzip.decompress(data)
return data.decode("utf-8", errors="replace")
def cookie_string(jar):
return "; ".join(f"{c.name}={c.value}" for c in jar)
def human_size(n):
for u in ("B", "KB", "MB", "GB"):
if n < 1024: return f"{n:.1f} {u}"
n /= 1024
return f"{n:.1f} TB"
# ─── 飞书核心 API ────────────────────────────────────────
def parse_share_url(url):
"""返回 (tenant, token, link_type:'file'|'folder')"""
m = re.match(r'https://([^.]+)\.feishu\.cn/file/([A-Za-z0-9_-]+)', url)
if m: return m.group(1), m.group(2), "file"
m = re.match(r'https://([^.]+)\.feishu\.cn/drive/folder/([A-Za-z0-9_-]+)', url)
if m: return m.group(1), m.group(2), "folder"
return None, None, None
def fetch_session(share_url):
"""访问分享页拿匿名 session cookie"""
jar = http.cookiejar.CookieJar()
opener = make_opener(jar)
req = urllib.request.Request(share_url)
req.add_header("User-Agent", UA)
req.add_header("Accept", "text/html,*/*")
opener.open(req, timeout=15).read()
return jar
def list_folder(tenant, folder_token, jar, page_label=""):
"""
v3 API 列出文件夹内容 (单页)
GET /space/api/explorer/v3/children/list/?token=xxx&length=50&...
"""
base = f"https://{tenant}.feishu.cn"
params = ["length=50", "asc=1", "rank=5", f"token={folder_token}"]
for t in LIST_OBJ_TYPES:
params.append(f"obj_type={t}")
if page_label:
params.append(f"last_label={quote(page_label, safe='')}")
url = f"{base}/space/api/explorer/v3/children/list/?{'&'.join(params)}"
opener = make_opener(jar)
req = urllib.request.Request(url)
req.add_header("User-Agent", UA)
req.add_header("Accept", "application/json, text/plain, */*")
req.add_header("Referer", f"{base}/drive/folder/{folder_token}")
resp = opener.open(req, timeout=15)
data = json.loads(decode_body(resp))
if data.get("code") != 0:
raise RuntimeError(f"API error: {data.get('msg')}")
d = data["data"]
nodes = d.get("entities", {}).get("nodes", {})
node_list = d.get("node_list", [])
items = []
for nid in node_list:
node = nodes.get(nid, {})
obj_type = node.get("type", -1)
obj_token = node.get("obj_token", "")
name = node.get("name", "unknown")
extra = node.get("extra", {})
try: size = int(extra.get("size", "0"))
except: size = 0
items.append({
"name": name, "obj_token": obj_token, "type": obj_type,
"size": size, "url": node.get("url", ""),
"is_folder": obj_type == 0,
"type_name": OBJ_TYPES.get(obj_type, f"❓ type={obj_type}"),
})
# 排除文件夹自身节点
items = [it for it in items if it["obj_token"] != folder_token]
return items, d.get("has_more", False), d.get("last_label", "")
def list_folder_all(tenant, folder_token, jar):
"""分页获取文件夹全部内容"""
all_items, label = [], ""
while True:
items, has_more, label = list_folder(tenant, folder_token, jar, label)
all_items.extend(items)
if not has_more: break
return all_items
def walk_folder(tenant, folder_token, jar, prefix="", depth=0):
"""递归遍历, 返回扁平列表 [{..., path:"a/b/file.txt"}]"""
if depth > 10: # 防止无限递归
return []
items = list_folder_all(tenant, folder_token, jar)
result = []
for it in items:
if it["is_folder"]:
sub = walk_folder(tenant, it["obj_token"], jar,
prefix=f"{prefix}{it['name']}/", depth=depth+1)
result.extend(sub)
else:
it["path"] = f"{prefix}{it['name']}"
result.append(it)
return result
def probe_file(tenant, obj_token, jar, referer):
"""Range 探测文件名 + 大小 (只取1字节)"""
dl_url = f"https://{tenant}.feishu.cn/space/api/box/stream/download/all/{obj_token}"
opener = make_opener(jar)
req = urllib.request.Request(dl_url)
req.add_header("User-Agent", UA)
req.add_header("Referer", referer)
req.add_header("Range", "bytes=0-0")
resp = opener.open(req, timeout=15)
cd = resp.headers.get("Content-Disposition", "")
cr = resp.headers.get("Content-Range", "")
resp.read()
filename = ""
m = re.search(r"filename\*=UTF-8''(.+?)(?:;|$)", cd)
if m: filename = unquote(m.group(1).strip())
if not filename:
m = re.search(r'filename="?([^";]+)"?', cd)
if m: filename = unquote(m.group(1).strip())
total = 0
m = re.search(r'/(\d+)', cr)
if m: total = int(m.group(1))
return filename, total
# ─── aria2 RPC ───────────────────────────────────────────
def aria2_add(dl_url, cs, referer, filename, out_dir=None):
opts = {"header": [f"Cookie: {cs}", f"Referer: {referer}", f"User-Agent: {UA}"]}
if filename: opts["out"] = filename
if out_dir: opts["dir"] = out_dir
payload = json.dumps({
"jsonrpc": "2.0", "id": str(uuid.uuid4()),
"method": "aria2.addUri",
"params": [f"token:{ARIA2_SECRET}", [dl_url], opts],
}).encode()
req = urllib.request.Request(ARIA2_RPC_URL, data=payload,
headers={"Content-Type": "application/json"})
resp = urllib.request.urlopen(req, timeout=10)
return json.loads(resp.read().decode()).get("result", "")
def push_one(dl_url, cs, referer, filename, out_dir, quiet=False):
try:
gid = aria2_add(dl_url, cs, referer, filename, out_dir)
if gid:
if not quiet: print(f" [✓] GID={gid} {filename}")
return True
except urllib.error.URLError:
if not quiet:
print(f" [✗] Motrix 未启动, RPC: {ARIA2_RPC_URL}")
except Exception as e:
if not quiet: print(f" [✗] {e}")
return False
def print_aria2c(dl_url, cs, referer, filename, out_dir):
print(f'aria2c --header="Cookie: {cs}" \\')
print(f' --header="Referer: {referer}" \\')
print(f' --header="User-Agent: {UA}" \\')
if filename: print(f' -o "{filename}" \\')
if out_dir: print(f' -d "{out_dir}" \\')
print(f' "{dl_url}"')
# ─── 主流程 ──────────────────────────────────────────────
def handle_file(tenant, token, jar, args):
share_url = f"https://{tenant}.feishu.cn/file/{token}"
dl_url = f"https://{tenant}.feishu.cn/space/api/box/stream/download/all/{token}"
cs = cookie_string(jar)
print(f"[2/3] 探测文件 ...")
filename, size = probe_file(tenant, token, jar, share_url)
print(f" {filename} ({human_size(size)})")
if args.list: return
if args.aria2c:
print_aria2c(dl_url, cs, share_url, filename, args.dir); return
print(f"[3/3] 推送到 Motrix ...")
if not push_one(dl_url, cs, share_url, filename, args.dir):
print(f"\n 降级输出 aria2c 命令:\n")
print_aria2c(dl_url, cs, share_url, filename, args.dir)
def handle_folder(tenant, token, jar, args):
base = f"https://{tenant}.feishu.cn"
cs = cookie_string(jar)
print(f"[2/4] 递归扫描文件夹 ...")
all_files = walk_folder(tenant, token, jar)
downloadable = [f for f in all_files if f["type"] == 12]
skipped = [f for f in all_files if f["type"] != 12]
print(f"{len(all_files)} 项: "
f"{len(downloadable)} 可下载, {len(skipped)} 在线文档(跳过)")
if skipped:
print(f"\n ⏭ 跳过的在线文档:")
for f in skipped:
print(f" {f['type_name']} {f['path']}")
if not downloadable:
print("\n 没有可下载的文件"); return
# 探测真实文件名和大小
print(f"\n[3/4] 探测文件信息 ...")
total_size = 0
for f in downloadable:
referer = f.get("url", f"{base}/drive/folder/{token}")
try:
real_name, size = probe_file(tenant, f["obj_token"], jar, referer)
f["real_name"] = real_name or f["name"]
f["size"] = size or f["size"]
except:
f["real_name"] = f["name"]
total_size += f["size"]
# 打印文件列表
print(f"\n {''*60}")
print(f" {'#':>3} {'文件名':<35} {'大小':>10} 路径")
print(f" {''*60}")
for i, f in enumerate(downloadable):
sz = human_size(f["size"]) if f["size"] else " ?"
print(f" {i+1:>3} {f['real_name']:<35} {sz:>10} {f['path']}")
print(f" {''*60}")
print(f" 合计: {len(downloadable)} 文件, {human_size(total_size)}")
if args.list: return
# 下载
print(f"\n[4/4] {'aria2c 命令' if args.aria2c else '推送 Motrix'} ...")
ok = 0
for f in downloadable:
dl_url = f"{base}/space/api/box/stream/download/all/{f['obj_token']}"
sub = os.path.dirname(f["path"])
out_dir = os.path.join(args.dir, sub) if args.dir and sub else (args.dir or None)
if args.aria2c:
print_aria2c(dl_url, cs, base, f["real_name"], out_dir)
print()
ok += 1
else:
if push_one(dl_url, cs, base, f["real_name"], out_dir, quiet=True):
ok += 1
print(f" [✓] {f['real_name']}")
else:
print(f" [✗] {f['real_name']} — Motrix 未响应")
print(f" 降级 aria2c:\n")
print_aria2c(dl_url, cs, base, f["real_name"], out_dir)
return # Motrix 挂了就不继续了
print(f"\n 完成! {ok}/{len(downloadable)}")
# ─── 入口 ────────────────────────────────────────────────
def main():
ap = argparse.ArgumentParser(description="飞书分享解析下载器 v2")
ap.add_argument("url", help="飞书分享链接 (文件/文件夹)")
ap.add_argument("-d", "--dir", default=None, help="下载目录")
ap.add_argument("--list", action="store_true", help="仅列出,不下载")
ap.add_argument("--aria2c", action="store_true", help="输出 aria2c 命令")
args = ap.parse_args()
tenant, token, lt = parse_share_url(args.url)
if not token:
print(f"[✗] 不支持的链接: {args.url}")
print(f" 格式: https://xxx.feishu.cn/file/xxxToken")
print(f" https://xxx.feishu.cn/drive/folder/xxxToken")
sys.exit(1)
print(f"\n{'📄' if lt=='file' else '📁'} 飞书分享解析 [{lt}] {tenant}/{token}")
print(f"[1/{3 if lt=='file' else 4}] 获取匿名会话 ...")
jar = fetch_session(args.url)
print(f" {sum(1 for _ in jar)} cookies")
if lt == "file":
handle_file(tenant, token, jar, args)
else:
handle_folder(tenant, token, jar, args)
print()
if __name__ == "__main__":
main()

View File

@@ -129,130 +129,15 @@ public class PanDomainTemplateTest {
wsPattern.matcher("https://www.evil.com/f/abc123").matches());
}
@Test
public void testLzPatternWebgetstore() {
Pattern lzPattern = PanDomainTemplate.LZ.getPattern();
// webgetstore.com 以前遗漏,现已补入
Matcher m1 = lzPattern.matcher("https://webgetstore.com/somekey");
assertTrue("LZ should match webgetstore.com", m1.find());
assertEquals("somekey", m1.group("KEY"));
Matcher m2 = lzPattern.matcher("https://www.webgetstore.com/somekey");
assertTrue("LZ should match www.webgetstore.com", m2.find());
assertEquals("somekey", m2.group("KEY"));
// t-is.cn 以前遗漏,现已补入
Matcher m3 = lzPattern.matcher("https://t-is.cn/somekey");
assertTrue("LZ should match t-is.cn", m3.find());
assertEquals("somekey", m3.group("KEY"));
Matcher m4 = lzPattern.matcher("https://www.t-is.cn/somekey");
assertTrue("LZ should match www.t-is.cn", m4.find());
assertEquals("somekey", m4.group("KEY"));
// 已有域名仍然正常匹配
Matcher m5 = lzPattern.matcher("https://www.lanzoul.com/somekey");
assertTrue("LZ should match existing domain lanzoul.com", m5.find());
assertEquals("somekey", m5.group("KEY"));
}
@Test
public void testLePatternFix() {
Pattern lePattern = PanDomainTemplate.LE.getPattern();
// lecloud.lenovo.com 应匹配
Matcher m1 = lePattern.matcher("https://lecloud.lenovo.com/share/abc123");
assertTrue("LE should match lecloud.lenovo.com", m1.find());
assertEquals("abc123", m1.group("KEY"));
// leclou.lenovo.com (去掉'd') 不应匹配(原 lecloud? 的 bug
assertFalse("LE should NOT match leclou.lenovo.com",
lePattern.matcher("https://leclou.lenovo.com/share/abc123").find());
}
@Test
public void testCowPatternFix() {
Pattern cowPattern = PanDomainTemplate.COW.getPattern();
// 正常域名
Matcher m1 = cowPattern.matcher("https://cowtransfer.com/s/abc123");
assertTrue("COW should match cowtransfer.com", m1.find());
assertEquals("abc123", m1.group("KEY"));
Matcher m2 = cowPattern.matcher("https://share.cowtransfer.com/s/abc123");
assertTrue("COW should match share.cowtransfer.com", m2.find());
assertEquals("abc123", m2.group("KEY"));
// 潜在的URL注入`(.*)` 是贪婪捕获组,可匹配 `evil.com/redirect/` 等前缀,
// 使形如 `https://evil.com/redirect/cowtransfer.com/s/key` 的 URL 被误识别。
// 修复后改为 `(?:[a-zA-Z\d-]+\.)?` 仅匹配一级合法子域名(可选),消除误匹配。
assertFalse("COW should NOT match redirect URLs containing cowtransfer.com in path",
cowPattern.matcher("https://evil.com/redirect/cowtransfer.com/s/abc").find());
}
@Test
public void testMnePatternFix() {
Pattern mnePattern = PanDomainTemplate.MNE.getPattern();
// 带 #/ 前缀的完整网页链接(修复前因 (y.) 未转义而存在 bug
Matcher m1 = mnePattern.matcher("https://music.163.com/#/song?id=12345");
assertTrue("MNE should match #/song format", m1.find());
assertEquals("12345", m1.group("KEY"));
// 带 m/ 前缀的移动端链接
Matcher m2 = mnePattern.matcher("https://music.163.com/m/song?id=12345");
assertTrue("MNE should match m/song format", m2.find());
assertEquals("12345", m2.group("KEY"));
// y.music.163.com 子域名
Matcher m3 = mnePattern.matcher("https://y.music.163.com/song?id=12345");
assertTrue("MNE should match y.music.163.com", m3.find());
assertEquals("12345", m3.group("KEY"));
// 原 (y.) 中 `.` 未转义(`.` 匹配任意字符):对于 `yXmusic.163.com`
// `(y.)` 会消费 `yX`y + 任意字符),剩余 `music.163.com` 再被 `music\.163\.com` 匹配,导致误匹配。
// 修复后 `(y\.)` 要求字面 `.``yX` 中 X ≠ `.` 无法匹配,不再误匹配。
assertFalse("MNE should NOT match yXmusic.163.com (old (y.) could erroneously match via backtracking)",
mnePattern.matcher("https://yXmusic.163.com/song?id=12345").find());
}
@Test
public void testP115PatternFix() {
Pattern p115Pattern = PanDomainTemplate.P115.getPattern();
// 正常匹配
Matcher m1 = p115Pattern.matcher("https://115.com/s/abc123");
assertTrue("P115 should match 115.com", m1.find());
assertEquals("abc123", m1.group("KEY"));
Matcher m2 = p115Pattern.matcher("https://anxia.com/s/abc123");
assertTrue("P115 should match anxia.com", m2.find());
assertEquals("abc123", m2.group("KEY"));
// 原 .com 未转义时 115Xcom 会被误匹配(现已修复)
assertFalse("P115 should NOT match 115Xcom",
p115Pattern.matcher("https://115Xcom/s/abc123").find());
}
@Test
public void testPgdSubdomain() {
Pattern pgdPattern = PanDomainTemplate.PGD.getPattern();
// 标准链接
Matcher m1 = pgdPattern.matcher("https://drive.google.com/file/d/abc123/view?usp=sharing");
assertTrue("PGD should match standard drive.google.com", m1.find());
assertEquals("abc123", m1.group("KEY"));
// 带子域名的链接(修复后支持)
Matcher m2 = pgdPattern.matcher("https://adsd.drive.google.com/file/d/151bR-nk-tOBm9QAFaozJIVt2WYyCMkoz/view");
assertTrue("PGD should match subdomain.drive.google.com", m2.find());
assertEquals("151bR-nk-tOBm9QAFaozJIVt2WYyCMkoz", m2.group("KEY"));
}
@Test
public void verifyDuplicates() {
Matcher matcher = compile("https://(?:[a-zA-Z\\d-]+\\.)?drive\\.google\\.com/file/d/(?<KEY>.+)/view(\\?usp=(sharing|drive_link))?")
.matcher("https://adsd.drive.google.com/file/d/151bR-nk-tOBm9QAFaozJIVt2WYyCMkoz/view");
if (matcher.find()) {
System.out.println(matcher.group());
System.out.println(matcher.group("KEY"));
}
// 校验重复
Set<String> collect =
Arrays.stream(PanDomainTemplate.values()).map(PanDomainTemplate::getRegex).collect(Collectors.toSet());

View File

@@ -1,185 +0,0 @@
package cn.qaiu.lz.common.util;
import cn.qaiu.lz.web.model.SysUser;
import io.vertx.core.json.JsonObject;
import javax.crypto.Mac;
import javax.crypto.spec.SecretKeySpec;
import java.nio.charset.StandardCharsets;
import java.security.InvalidKeyException;
import java.security.NoSuchAlgorithmException;
import java.time.Instant;
import java.time.LocalDateTime;
import java.time.ZoneId;
import java.util.Base64;
import java.util.Date;
/**
* JWT工具类用于生成和验证JWT token
*/
public class JwtUtil {
private static final long EXPIRE_TIME = 24 * 60 * 60 * 1000; // token过期时间24小时
private static final String SECRET_KEY = "netdisk-fast-download-jwt-secret-key"; // 密钥
private static final String ALGORITHM = "HmacSHA256";
/**
* 生成JWT token
*
* @param user 用户信息
* @return JWT token
*/
public static String generateToken(SysUser user) {
long expireTime = getExpireTime();
// Header
JsonObject header = new JsonObject()
.put("alg", "HS256")
.put("typ", "JWT");
// Payload
JsonObject payload = new JsonObject()
.put("id", user.getId())
.put("username", user.getUsername())
.put("role", user.getRole())
.put("exp", expireTime)
.put("iat", System.currentTimeMillis())
.put("iss", "netdisk-fast-download");
// Base64 encode header and payload
String encodedHeader = Base64.getUrlEncoder().withoutPadding().encodeToString(header.encode().getBytes(StandardCharsets.UTF_8));
String encodedPayload = Base64.getUrlEncoder().withoutPadding().encodeToString(payload.encode().getBytes(StandardCharsets.UTF_8));
// Create signature
String signature = hmacSha256(encodedHeader + "." + encodedPayload, SECRET_KEY);
// Combine to form JWT
return encodedHeader + "." + encodedPayload + "." + signature;
}
/**
* 使用HMAC-SHA256算法生成签名
*
* @param data 要签名的数据
* @param key 密钥
* @return 签名
*/
private static String hmacSha256(String data, String key) {
try {
Mac sha256Hmac = Mac.getInstance(ALGORITHM);
SecretKeySpec secretKey = new SecretKeySpec(key.getBytes(StandardCharsets.UTF_8), ALGORITHM);
sha256Hmac.init(secretKey);
byte[] signedBytes = sha256Hmac.doFinal(data.getBytes(StandardCharsets.UTF_8));
return Base64.getUrlEncoder().withoutPadding().encodeToString(signedBytes);
} catch (NoSuchAlgorithmException | InvalidKeyException e) {
throw new RuntimeException("Error creating HMAC SHA256 signature", e);
}
}
/**
* 验证JWT token
*
* @param token JWT token
* @return 如果token有效返回true否则返回false
*/
public static boolean validateToken(String token) {
try {
String[] parts = token.split("\\.");
if (parts.length != 3) {
return false;
}
String encodedHeader = parts[0];
String encodedPayload = parts[1];
String signature = parts[2];
// 验证签名
String expectedSignature = hmacSha256(encodedHeader + "." + encodedPayload, SECRET_KEY);
if (!expectedSignature.equals(signature)) {
return false;
}
// 验证过期时间
String payload = new String(Base64.getUrlDecoder().decode(encodedPayload), StandardCharsets.UTF_8);
JsonObject payloadJson = new JsonObject(payload);
long expTime = payloadJson.getLong("exp", 0L);
return System.currentTimeMillis() < expTime;
} catch (Exception e) {
return false;
}
}
/**
* 从token中获取用户ID
*
* @param token JWT token
* @return 用户ID
*/
public static String getUserIdFromToken(String token) {
String[] parts = token.split("\\.");
if (parts.length != 3) {
return null;
}
// Base64解码
String payload = new String(Base64.getUrlDecoder().decode(parts[1]), StandardCharsets.UTF_8);
JsonObject jsonObject = new JsonObject(payload);
return jsonObject.getString("id");
}
/**
* 从token中获取用户名
*
* @param token JWT token
* @return 用户名
*/
public static String getUsernameFromToken(String token) {
String[] parts = token.split("\\.");
if (parts.length != 3) {
return null;
}
// Base64解码
String payload = new String(Base64.getUrlDecoder().decode(parts[1]), StandardCharsets.UTF_8);
JsonObject jsonObject = new JsonObject(payload);
return jsonObject.getString("username");
}
/**
* 从token中获取用户角色
*
* @param token JWT token
* @return 用户角色
*/
public static String getRoleFromToken(String token) {
String[] parts = token.split("\\.");
if (parts.length != 3) {
return null;
}
// Base64解码
String payload = new String(Base64.getUrlDecoder().decode(parts[1]), StandardCharsets.UTF_8);
JsonObject jsonObject = new JsonObject(payload);
return jsonObject.getString("role");
}
/**
* 获取过期时间
*
* @return 过期时间戳
*/
private static long getExpireTime() {
return System.currentTimeMillis() + EXPIRE_TIME;
}
/**
* 将过期时间戳转换为LocalDateTime
*
* @param expireTime 过期时间戳
* @return LocalDateTime
*/
public static LocalDateTime getExpireTimeAsLocalDateTime(long expireTime) {
return LocalDateTime.ofInstant(Instant.ofEpochMilli(expireTime), ZoneId.systemDefault());
}
}

View File

@@ -1,60 +0,0 @@
package cn.qaiu.lz.web.model;
import cn.qaiu.db.ddl.Table;
import cn.qaiu.lz.common.ToJson;
import com.fasterxml.jackson.annotation.JsonFormat;
import com.fasterxml.jackson.annotation.JsonIgnore;
import io.vertx.codegen.annotations.DataObject;
import io.vertx.core.json.JsonObject;
import lombok.Data;
import lombok.NoArgsConstructor;
import java.time.LocalDateTime;
import java.time.format.DateTimeFormatter;
@Data
@DataObject
@NoArgsConstructor
@Table("sys_user")
public class SysUser implements ToJson {
private String id;
private String username;
private String password;
private String email;
private String phone;
private String avatar;
// 用户状态0-禁用1-正常
private Integer status;
// 用户角色admin-管理员user-普通用户
private String role;
// 最后登录时间
@JsonFormat(pattern = "yyyy-MM-dd'T'HH:mm:ss")
private LocalDateTime lastLoginTime;
private Integer age;
@JsonFormat(pattern = "yyyy-MM-dd'T'HH:mm:ss")
private LocalDateTime createTime;
public SysUser(JsonObject json) {
this.id = json.getString("id");
this.username = json.getString("username");
this.password = json.getString("password");
this.email = json.getString("email");
this.phone = json.getString("phone");
this.avatar = json.getString("avatar");
this.status = json.getInteger("status");
this.role = json.getString("role");
this.age = json.getInteger("age");
if (json.getString("createTime") != null) {
this.createTime = LocalDateTime.parse(json.getString("createTime"));
}
if (json.getString("lastLoginTime") != null) {
this.lastLoginTime = LocalDateTime.parse(json.getString("lastLoginTime"));
}
}
}

View File

@@ -1,51 +0,0 @@
package cn.qaiu.lz.web.service;
import cn.qaiu.lz.web.model.SysUser;
import cn.qaiu.vx.core.base.BaseAsyncService;
import io.vertx.codegen.annotations.ProxyGen;
import io.vertx.core.Future;
import io.vertx.core.json.JsonObject;
/**
* 用户服务接口
* <br>Create date 2021/8/27 14:06
*
* @author <a href="https://qaiu.top">QAIU</a>
*/
@ProxyGen
public interface UserService extends BaseAsyncService {
/**
* 用户登录
* @param user 包含用户名和密码的用户对象
* @return 登录成功返回用户信息和token失败返回错误信息
*/
Future<JsonObject> login(SysUser user);
/**
* 根据用户名获取用户信息
* @param username 用户名
* @return 用户信息
*/
Future<SysUser> getUserByUsername(String username);
/**
* 创建新用户
* @param user 用户信息
* @return 创建成功返回用户信息,失败返回错误信息
*/
Future<SysUser> createUser(SysUser user);
/**
* 更新用户信息
* @param user 用户信息
* @return 更新成功返回用户信息,失败返回错误信息
*/
Future<SysUser> updateUser(SysUser user);
/**
* 验证token
* @param token JWT token
* @return 验证成功返回用户信息,失败返回错误信息
*/
Future<JsonObject> validateToken(String token);
}

View File

@@ -1,414 +0,0 @@
package cn.qaiu.lz.web.service.impl;
import cn.qaiu.db.pool.JDBCPoolInit;
import cn.qaiu.lz.common.util.JwtUtil;
import cn.qaiu.lz.common.util.PasswordUtil;
import cn.qaiu.lz.web.model.SysUser;
import cn.qaiu.lz.web.service.UserService;
import cn.qaiu.vx.core.annotaions.Service;
import io.vertx.core.Future;
import io.vertx.core.Promise;
import io.vertx.core.json.JsonObject;
import io.vertx.jdbcclient.JDBCPool;
import io.vertx.sqlclient.Row;
import io.vertx.sqlclient.RowSet;
import io.vertx.sqlclient.Tuple;
import lombok.extern.slf4j.Slf4j;
import java.sql.Timestamp;
import java.time.LocalDateTime;
import java.time.ZoneId;
import java.util.UUID;
/**
* 用户服务实现类
* <br>Create date 2021/8/27 14:09
*
* @author <a href="https://qaiu.top">QAIU</a>
*/
@Slf4j
@Service
public class UserServiceImpl implements UserService {
private final JDBCPool jdbcPool = JDBCPoolInit.instance().getPool();
// 初始化方法,确保管理员用户存在
public void init() {
// 检查管理员用户是否存在
getUserByUsername("admin")
.onSuccess(user -> {
log.info("管理员用户已存在");
})
.onFailure(err -> {
// 创建管理员用户
SysUser admin = new SysUser();
admin.setId(UUID.randomUUID().toString());
admin.setUsername("admin");
admin.setPassword(PasswordUtil.hashPassword("admin123"));
admin.setEmail("admin@example.com");
admin.setRole("admin");
admin.setStatus(1);
admin.setCreateTime(LocalDateTime.now());
createUser(admin)
.onSuccess(result -> log.info("管理员用户创建成功"))
.onFailure(error -> log.error("管理员用户创建失败", error));
});
}
// 新增一个工具方法来过滤敏感信息
private SysUser filterSensitiveInfo(SysUser user) {
if (user != null) {
SysUser filtered = new SysUser();
// 复制除密码外的所有字段
filtered.setId(user.getId());
filtered.setUsername(user.getUsername());
filtered.setEmail(user.getEmail());
filtered.setPhone(user.getPhone());
filtered.setAvatar(user.getAvatar());
filtered.setRole(user.getRole());
filtered.setStatus(user.getStatus());
filtered.setCreateTime(user.getCreateTime());
filtered.setLastLoginTime(user.getLastLoginTime());
return filtered;
}
return null;
}
// 将Row转换为SysUser对象
private SysUser rowToUser(Row row) {
if (row == null) {
return null;
}
SysUser user = new SysUser();
user.setId(row.getString("id"));
user.setUsername(row.getString("username"));
user.setPassword(row.getString("password"));
user.setEmail(row.getString("email"));
user.setPhone(row.getString("phone"));
user.setAvatar(row.getString("avatar"));
user.setRole(row.getString("role"));
user.setStatus(row.getInteger("status"));
// 处理日期时间字段
LocalDateTime createTime = row.getLocalDateTime("create_time");
if (createTime != null) {
user.setCreateTime(createTime);
}
LocalDateTime lastLoginTime = row.getLocalDateTime("last_login_time");
if (lastLoginTime != null) {
user.setLastLoginTime(lastLoginTime);
}
return user;
}
@Override
public Future<JsonObject> login(SysUser user) {
// 参数校验
if (user == null || user.getUsername() == null || user.getPassword() == null) {
return Future.succeededFuture(new JsonObject()
.put("success", false)
.put("message", "用户名和密码不能为空"));
}
Promise<JsonObject> promise = Promise.promise();
// 查询用户
String sql = "SELECT * FROM sys_user WHERE username = ?";
jdbcPool.preparedQuery(sql)
.execute(Tuple.of(user.getUsername()))
.onSuccess(rows -> {
if (rows.size() == 0) {
promise.complete(new JsonObject()
.put("success", false)
.put("message", "用户不存在"));
return;
}
Row row = rows.iterator().next();
SysUser existUser = rowToUser(row);
// 验证密码
if (!PasswordUtil.checkPassword(user.getPassword(), existUser.getPassword())) {
promise.complete(new JsonObject()
.put("success", false)
.put("message", "密码错误"));
return;
}
// 更新最后登录时间
LocalDateTime now = LocalDateTime.now();
existUser.setLastLoginTime(now);
// 更新数据库中的最后登录时间
String updateSql = "UPDATE sys_user SET last_login_time = ? WHERE username = ?";
jdbcPool.preparedQuery(updateSql)
.execute(Tuple.of(
Timestamp.from(now.atZone(ZoneId.systemDefault()).toInstant()),
existUser.getUsername()
))
.onFailure(err -> log.error("更新最后登录时间失败", err));
// 生成token
String token = JwtUtil.generateToken(existUser);
// 返回用户信息和token
JsonObject value = JsonObject.mapFrom(existUser);
value.remove("password");
promise.complete(new JsonObject()
.put("success", true)
.put("message", "登录成功")
.put("token", token)
.put("user", value));
})
.onFailure(err -> {
log.error("登录查询失败", err);
promise.complete(new JsonObject()
.put("success", false)
.put("message", "登录失败: " + err.getMessage()));
});
return promise.future();
}
@Override
public Future<SysUser> getUserByUsername(String username) {
if (username == null || username.isEmpty()) {
return Future.failedFuture("用户名不能为空");
}
Promise<SysUser> promise = Promise.promise();
String sql = "SELECT * FROM sys_user WHERE username = ?";
jdbcPool.preparedQuery(sql)
.execute(Tuple.of(username))
.onSuccess(rows -> {
if (rows.size() == 0) {
promise.fail("用户不存在");
return;
}
Row row = rows.iterator().next();
SysUser user = rowToUser(row);
promise.complete(filterSensitiveInfo(user));
})
.onFailure(err -> {
log.error("查询用户失败", err);
promise.fail("查询用户失败: " + err.getMessage());
});
return promise.future();
}
@Override
public Future<SysUser> createUser(SysUser user) {
// 参数校验
if (user == null || user.getUsername() == null || user.getPassword() == null) {
return Future.failedFuture("用户名和密码不能为空");
}
Promise<SysUser> promise = Promise.promise();
// 先检查用户是否已存在
String checkSql = "SELECT COUNT(*) as count FROM sys_user WHERE username = ?";
jdbcPool.preparedQuery(checkSql)
.execute(Tuple.of(user.getUsername()))
.onSuccess(rows -> {
Row row = rows.iterator().next();
long count = row.getLong("count");
if (count > 0) {
promise.fail("用户名已存在");
return;
}
// 设置用户ID和创建时间
if (user.getId() == null) {
user.setId(UUID.randomUUID().toString());
}
if (user.getCreateTime() == null) {
user.setCreateTime(LocalDateTime.now());
}
// 设置默认角色和状态
if (user.getRole() == null) {
user.setRole("user");
}
if (user.getStatus() == null) {
user.setStatus(1);
}
// 对密码进行加密
String plainPassword = user.getPassword();
user.setPassword(PasswordUtil.hashPassword(plainPassword));
// 插入用户
String insertSql = "INSERT INTO sys_user (id, username, password, email, phone, avatar, role, status, create_time) " +
"VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)";
jdbcPool.preparedQuery(insertSql)
.execute(Tuple.of(
user.getId(),
user.getUsername(),
user.getPassword(),
user.getEmail(),
user.getPhone(),
user.getAvatar(),
user.getRole(),
user.getStatus(),
Timestamp.from(user.getCreateTime().atZone(ZoneId.systemDefault()).toInstant())
))
.onSuccess(result -> {
promise.complete(filterSensitiveInfo(user));
})
.onFailure(err -> {
log.error("创建用户失败", err);
promise.fail("创建用户失败: " + err.getMessage());
});
})
.onFailure(err -> {
log.error("检查用户是否存在失败", err);
promise.fail("创建用户失败: " + err.getMessage());
});
return promise.future();
}
@Override
public Future<SysUser> updateUser(SysUser user) {
// 参数校验
if (user == null || user.getUsername() == null) {
return Future.failedFuture("用户名不能为空");
}
Promise<SysUser> promise = Promise.promise();
// 先检查用户是否存在
String checkSql = "SELECT * FROM sys_user WHERE username = ?";
jdbcPool.preparedQuery(checkSql)
.execute(Tuple.of(user.getUsername()))
.onSuccess(rows -> {
if (rows.size() == 0) {
promise.fail("用户不存在");
return;
}
Row row = rows.iterator().next();
SysUser existUser = rowToUser(row);
// 构建更新SQL
StringBuilder updateSql = new StringBuilder("UPDATE sys_user SET ");
Tuple params = Tuple.tuple();
if (user.getEmail() != null) {
updateSql.append("email = ?, ");
params.addValue(user.getEmail());
}
if (user.getPhone() != null) {
updateSql.append("phone = ?, ");
params.addValue(user.getPhone());
}
if (user.getAvatar() != null) {
updateSql.append("avatar = ?, ");
params.addValue(user.getAvatar());
}
if (user.getStatus() != null) {
updateSql.append("status = ?, ");
params.addValue(user.getStatus());
}
if (user.getRole() != null) {
updateSql.append("role = ?, ");
params.addValue(user.getRole());
}
if (user.getPassword() != null) {
updateSql.append("password = ?, ");
params.addValue(PasswordUtil.hashPassword(user.getPassword()));
}
// 移除最后的逗号和空格
String sql = updateSql.toString();
if (sql.endsWith(", ")) {
sql = sql.substring(0, sql.length() - 2);
}
// 如果没有要更新的字段,直接返回
if (params.size() == 0) {
promise.complete(filterSensitiveInfo(existUser));
return;
}
// 添加WHERE条件
sql += " WHERE username = ?";
params.addValue(user.getUsername());
// 执行更新
jdbcPool.preparedQuery(sql)
.execute(params)
.onSuccess(result -> {
// 重新查询用户信息
getUserByUsername(user.getUsername())
.onSuccess(promise::complete)
.onFailure(promise::fail);
})
.onFailure(err -> {
log.error("更新用户失败", err);
promise.fail("更新用户失败: " + err.getMessage());
});
})
.onFailure(err -> {
log.error("查询用户失败", err);
promise.fail("更新用户失败: " + err.getMessage());
});
return promise.future();
}
@Override
public Future<JsonObject> validateToken(String token) {
if (token == null || token.isEmpty()) {
return Future.succeededFuture(new JsonObject()
.put("success", false)
.put("message", "Token不能为空"));
}
// 验证token
boolean isValid = JwtUtil.validateToken(token);
if (!isValid) {
return Future.succeededFuture(new JsonObject()
.put("success", false)
.put("message", "Token无效或已过期"));
}
// 获取用户信息
String username = JwtUtil.getUsernameFromToken(token);
Promise<JsonObject> promise = Promise.promise();
getUserByUsername(username)
.onSuccess(user -> {
promise.complete(new JsonObject()
.put("success", true)
.put("message", "Token有效")
.put("user", JsonObject.mapFrom(user)));
})
.onFailure(err -> {
promise.complete(new JsonObject()
.put("success", false)
.put("message", "用户不存在"));
});
return promise.future();
}
}