Compare commits

...
Author SHA1 Message Date
Cursor Agentandqaiu 1ab9df7826 fix: guide Authorization when 123 password login hits captcha
123 pan username/password sign-in that returns captcha or risk-control
now fails with a user-facing hint to configure Authorization (Bearer/JWT),
instead of the raw upstream message. Wrong-password and network errors stay
distinct. No captcha solving, QR login, or retries.

Co-authored-by: qaiu <[email protected]>
2026-09-27 22:08:16 +00:00
qaiu ab8b687837 Merge pull request #231 from qaiu/cursor/release-047-9e8b
release: v0.4.7
2026-09-25 16:35:29 +08:00
Cursor Agentandqaiu 7616bf3144 release: 0.4.7 Lanzou host rewrite and apifile ajax
Co-authored-by: qaiu <[email protected]>
2026-09-25 08:34:52 +00:00
qaiu 01d7956de5 Merge pull request #229 from qaiu/cursor/lanzou-skip-wwww-rewrite-d50d
fix(parser): 蓝奏个性域名保留原主机,文件直链走 apifile
2026-09-25 16:33:05 +08:00
Cursor Agentandqaiu 78e53c076e fix(parser): 蓝奏文件 ajax 优先使用页面里的 apifile 绝对地址
个性域名文件页把 ajaxfile.php 写到 apifile.lanzouw.com。相对路径打到页面源站会空响应,直链拿不到。绝对地址优先,apifile 放进文件 ajax 兜底且排在四 w 之前;目录列表仍不走 apifile。

Co-authored-by: qaiu <[email protected]>
2026-09-25 08:27:58 +00:00
Cursor Agentandqaiu 4d985cc96f fix(parser): 蓝奏个性域名不再强制改写到 wwww.lanzoux.com
a.lanzouw.com 的页面请求被改到四个 w 的主机后,部分出口会连接超时。
分享页 GET 保留原主机;ajax/filemore 再按 w1、www、wwww 顺序回退。

Co-authored-by: qaiu <[email protected]>
2026-09-25 06:46:11 +00:00
qaiu 13ccdb8adf 更新 README.md 2026-09-24 06:05:20 +08:00
qaiu ac1afcd35f 更新 README.md 2026-09-24 06:04:37 +08:00
11 changed files with 923 additions and 48 deletions
+5 -1
View File
@@ -18,6 +18,8 @@ QQ交流群:1017480890
![alt text](web-front/img/image.png)
> 本平台所有音乐解析工具不再维护,请移步[Sonder播放器](https://sodecode.qaiu.top)
> 需要百度,迅雷,UC,夸克的完整支持请使用[专业版](https://189.qaiu.top)
## 介绍
> netdisk-fast-download网盘直链解析可以把云盘分享链接转为直链,可广泛应用于各类下载站,资源站,个人博客,图床,APP下载更新,视频点播等领域。支持市面各大主流云盘的文件分享以及文件夹分享链接,已支持蓝奏云/蓝奏云优享/移动云云空间/小飞机盘/亿方云/123云盘/永硕E盘/Cloudreve等,支持加密分享,以及部分网盘文件夹分享。
@@ -236,6 +238,8 @@ auths:
```
> ⚠️ 注意:YAML 中 key 后面不写值(如 `authorization:` 空着)等同于没配置,不会生效,必须填入真实的账号密码或 token 内容。
>
> 若 123 云盘账号密码登录触发验证码或风控,解析会直接失败并提示改用 Authorization,不会尝试验证码。请改填上面的 `authorization` / `token`(浏览器 localStorage 的 `authorToken`,或请求头 `authorization` / Cookie `sso-token` 里的 JWT)。
如果只是临时调用一次,不想改动服务端配置,也可以用上面提到的 `auth` 参数临时传递(`authType` 可选 `password`/`accesstoken`/`authorization`),无需重启服务,仅本次请求生效。
@@ -459,7 +463,7 @@ docker run --rm -v /var/run/docker.sock:/var/run/docker.sock containrrr/watchtow
> 注意: netdisk-fast-download.service中的ExecStart的路径改为实际路径
```shell
cd ~
wget -O netdisk-fast-download.zip https://github.com/qaiu/netdisk-fast-download/releases/download/v0.4.6/netdisk-fast-download-linux-amd64.zip
wget -O netdisk-fast-download.zip https://github.com/qaiu/netdisk-fast-download/releases/download/v0.4.7/netdisk-fast-download-linux-amd64.zip
unzip netdisk-fast-download.zip
cd netdisk-fast-download
bash service-install.sh
@@ -109,6 +109,8 @@ URL解码 → Base64解码 → AES解密 → JSON对象
}
```
> 123云盘(`ye`)账号密码登录如果返回验证码或风控,解析会直接失败,并提示改用 Authorization,不会尝试验证码。请在浏览器登录后复制 `authorToken` / 请求头 `authorization` / Cookie `sso-token`,用 `authType=authorization` 或 `accesstoken` 传入,或写入 `app-dev.yml` 的 `auths.ye.authorization`。
#### 4. 自定义认证
```json
{
@@ -339,3 +341,4 @@ server:
## 更新日志
- **2026-02-05**: 初始版本,支持 accesstoken、cookie、password、custom 认证类型
- **2026-09-27**: 补充 123云盘账号密码登录触发验证码/风控时改用 Authorization 的说明
@@ -57,6 +57,8 @@
}
```
> 123云盘(`ye`)账号密码登录触发验证码/风控时,请改用 `authType=authorization` 或 `accesstoken`(`token` 填浏览器中的 Bearer token / JWT),或在 `app-dev.yml` 配置 `auths.ye.authorization`。解析不会尝试验证码。
### 自定义认证
```json
{
@@ -0,0 +1,270 @@
package cn.qaiu.parser;
import io.vertx.core.json.JsonArray;
import io.vertx.core.json.JsonObject;
import org.apache.commons.lang3.StringUtils;
import java.util.Locale;
/**
* 账号密码登录撞上验证码/风控时的用户提示。
* 只识别失败形态并引导改用 Authorization,不实现验证码求解、扫码或重试。
*/
public final class PasswordLoginRisk {
/**
* 123 云盘(ye)账号密码登录被验证码/风控拦住时返回给调用方的固定说明。
* 上游 code/message 会另附在这句话后面,便于和“密码错误”区分。
*/
public static final String AUTHORIZATION_HINT =
"账号密码登录触发了验证码/风控,已停止用户名密码登录(不会尝试验证码)。"
+ "请改为配置 Authorization(浏览器登录后的 Bearer token / JWT,"
+ "例如 localStorage 的 authorToken、请求头 authorization 或 Cookie 的 sso-token)。"
+ "静态配置写在 app-dev.yml 的 auths.ye.authorization(与 auths.ye.token 等价);"
+ "临时请求使用 authType=authorization 或 authType=accesstoken,token 填该令牌(不要重复带 Bearer 前缀)。"
+ "说明见 parser/doc/auth-param/。";
/**
* 上游文案命中这些片段时视为验证码/风控,而不是单纯的密码错误。
* 依据公开客户端(AList/OpenList)实际展示过的 123 登录失败文案,以及登录页上的滑块/人机验证提示。
*/
private static final String[] RISK_KEYWORDS = {
"验证码",
"风控",
"安全风险",
"安全验证",
"安全校验",
"滑块",
"滑动验证",
"拼图验证",
"短信验证",
"微信登录",
"微信进行登录",
"境外登录",
"需要验证",
"请验证",
"请你验证",
"进行验证",
"完成验证",
"二次验证",
"人机验证",
"操作频繁",
"请求过于频繁",
"请求频繁",
"captcha",
"recaptcha",
"risk control"
};
private PasswordLoginRisk() {
}
public static boolean isLoginSuccess(JsonObject json) {
if (json == null) {
return false;
}
Integer code = readCode(json);
return code != null && code == 200 && StringUtils.isNotBlank(readToken(json));
}
public static boolean indicatesCaptchaOrRisk(JsonObject json) {
if (json == null) {
return false;
}
if (hasTruthyRiskField(json) || hasTruthyRiskField(dataObject(json))) {
return true;
}
return textIndicatesCaptchaOrRisk(collectMessageText(json));
}
public static boolean textIndicatesCaptchaOrRisk(String text) {
if (StringUtils.isBlank(text)) {
return false;
}
String lower = text.toLowerCase(Locale.ROOT);
for (String keyword : RISK_KEYWORDS) {
if (lower.contains(keyword.toLowerCase(Locale.ROOT))) {
return true;
}
}
return false;
}
/**
* 非成功登录响应的用户可见说明。验证码/风控走 Authorization 引导,其余保持“登录失败: 上游文案”。
*/
public static String describeLoginFailure(JsonObject json) {
if (json == null) {
return "登录响应格式异常";
}
if (indicatesCaptchaOrRisk(json)) {
return AUTHORIZATION_HINT + " 上游返回:" + upstreamSummary(json);
}
Integer code = readCode(json);
if (code != null && code == 200) {
return "未获取到token";
}
String message = firstMessage(json);
if (StringUtils.isBlank(message)) {
return "登录失败";
}
return "登录失败: " + message;
}
public static String nonJsonLoginFailure(String body) {
if (textIndicatesCaptchaOrRisk(body)) {
return AUTHORIZATION_HINT + " 上游返回:" + truncate(body, 300);
}
return "登录响应格式异常: " + body;
}
private static String collectMessageText(JsonObject json) {
StringBuilder text = new StringBuilder();
appendMessage(text, json);
JsonObject data = dataObject(json);
if (data != null) {
appendMessage(text, data);
}
return text.toString();
}
private static void appendMessage(StringBuilder text, JsonObject json) {
append(text, json.getString("message"));
append(text, json.getString("msg"));
}
private static void append(StringBuilder text, String value) {
if (StringUtils.isNotBlank(value)) {
if (text.length() > 0) {
text.append(' ');
}
text.append(value);
}
}
private static boolean hasTruthyRiskField(JsonObject obj) {
if (obj == null) {
return false;
}
for (String key : obj.fieldNames()) {
if (!isRiskFieldName(key)) {
continue;
}
if (isTruthyRiskValue(obj.getValue(key))) {
return true;
}
}
return false;
}
private static boolean isRiskFieldName(String key) {
String lower = key.toLowerCase(Locale.ROOT);
return lower.contains("captcha")
|| lower.contains("vcode")
|| lower.contains("risk")
|| "needverify".equals(lower)
|| "need_verify".equals(lower)
|| "slideverify".equals(lower)
|| "verifycode".equals(lower)
|| "verify_code".equals(lower);
}
private static boolean isTruthyRiskValue(Object value) {
if (value == null) {
return false;
}
if (value instanceof Boolean) {
return (Boolean) value;
}
if (value instanceof Number) {
return ((Number) value).doubleValue() != 0d;
}
if (value instanceof CharSequence) {
String text = value.toString().trim();
if (text.isEmpty()) {
return false;
}
String lower = text.toLowerCase(Locale.ROOT);
return !"false".equals(lower) && !"0".equals(lower) && !"null".equals(lower) && !"none".equals(lower);
}
if (value instanceof JsonObject) {
return !((JsonObject) value).isEmpty();
}
if (value instanceof JsonArray) {
return !((JsonArray) value).isEmpty();
}
return true;
}
private static String upstreamSummary(JsonObject json) {
StringBuilder summary = new StringBuilder();
Integer code = readCode(json);
if (code != null) {
summary.append("code=").append(code);
}
String message = firstMessage(json);
if (StringUtils.isNotBlank(message)) {
if (summary.length() > 0) {
summary.append(", ");
}
summary.append("message=").append(message);
}
if (summary.length() == 0) {
summary.append(json.encode());
}
return truncate(summary.toString(), 300);
}
private static String firstMessage(JsonObject json) {
String message = json.getString("message");
if (StringUtils.isBlank(message)) {
message = json.getString("msg");
}
if (StringUtils.isBlank(message)) {
JsonObject data = dataObject(json);
if (data != null) {
message = data.getString("message");
if (StringUtils.isBlank(message)) {
message = data.getString("msg");
}
}
}
return message;
}
static String readToken(JsonObject json) {
JsonObject data = dataObject(json);
if (data == null) {
return null;
}
Object token = data.getValue("token");
return token == null ? null : token.toString();
}
private static JsonObject dataObject(JsonObject json) {
Object data = json.getValue("data");
return data instanceof JsonObject ? (JsonObject) data : null;
}
static Integer readCode(JsonObject json) {
Object code = json.getValue("code");
if (code instanceof Number) {
return ((Number) code).intValue();
}
if (code instanceof String && StringUtils.isNumeric(((String) code).trim())) {
return Integer.parseInt(((String) code).trim());
}
return null;
}
private static String truncate(String value, int max) {
if (value == null) {
return "";
}
String trimmed = value.trim();
if (trimmed.length() <= max) {
return trimmed;
}
return trimmed.substring(0, max) + "...";
}
}
@@ -7,6 +7,7 @@ import cn.qaiu.parser.PanBase;
import cn.qaiu.util.*;
import io.netty.handler.codec.http.cookie.DefaultCookie;
import io.vertx.core.Future;
import io.vertx.core.Handler;
import io.vertx.core.MultiMap;
import io.vertx.core.Promise;
import io.vertx.core.buffer.Buffer;
@@ -41,9 +42,37 @@ public class LzTool extends PanBase {
private final WebClientSession webClientSession;
/** 实测服务器出口 IP 上 wwww.lanzoux.com 可用,且个性域名目录内文件 ID 也能打开。 */
public static final String SHARE_URL_PREFIX = "https://wwww.lanzoux.com/";
private static final String SHARE_ORIGIN = "https://wwww.lanzoux.com";
/**
* 没有原始分享页主机时才使用(目录内文件 ID、shareKey 占位)。
* 与 PanDomainTemplate.LZ 标准模板一致:{@code https://w1.lanzn.com/{shareKey}}。
* 已有分享页不要改写到 wwww.lanzoux.com,部分出口连四个 w 的域名会超时。
*/
public static final String SHARE_URL_PREFIX = "https://w1.lanzn.com/";
/** 页面 URL 解析失败时的源站兜底,与 {@link #SHARE_URL_PREFIX} 同主机。 */
private static final String SHARE_ORIGIN = "https://w1.lanzn.com";
/**
* 目录 filemoreajax.php 换域顺序。个性域名上会立刻返回「已超时」。
* wwww 只放最后,避免单一主机超时直接失败。
* 文件 ajax 走 {@link #FILE_AJAX_FALLBACK_ORIGINS},不要把 apifile 混进目录列表。
*/
static final List<String> AJAX_FALLBACK_ORIGINS = List.of(
"https://w1.lanzn.com",
"https://www.lanzoux.com",
"https://wwww.lanzoux.com"
);
/**
* 文件页 iframe / 密码页里的 ajaxfile.php 经常是绝对地址
* {@code https://apifile.lanzouw.com/ajaxfile.php?file=…}。
* 相对路径打到页面源站或 w1/www 会空响应。apifile 放在文件 ajax 兜底的最前,
* 页面源站空响应后立刻换过去,不在四 w 上耗光超时。
*/
static final String APIFILE_ORIGIN = "https://apifile.lanzouw.com";
static final List<String> FILE_AJAX_FALLBACK_ORIGINS = List.of(
APIFILE_ORIGIN,
"https://w1.lanzn.com",
"https://www.lanzoux.com",
"https://wwww.lanzoux.com"
);
/** 分享页 / ajax 请求超时 */
private static final long REQUEST_TIMEOUT = 8000;
/** 下载域跳转与二次验证超时,链路更长 */
@@ -54,6 +83,10 @@ public class LzTool extends PanBase {
private static final Pattern P_AJAXDATA = Pattern.compile("ajaxdata\\s*=\\s*'([^']+)'");
private static final Pattern P_WEBSIGN = Pattern.compile("'websign'\\s*:\\s*'([^']*)'");
private static final Pattern P_WEBPAGE = Pattern.compile("[?&]webpage=([^&\"'\\s#]+)");
/** 页面脚本里的绝对 ajax,例如 https://apifile.lanzouw.com/ajaxfile.php?file=123 */
private static final Pattern P_AJAX_ABSOLUTE = Pattern.compile(
"['\"]((?:https?:)?//[^'\"\\s<>]+/ajax(?:m|file)\\.php\\?file=\\d+)['\"]",
Pattern.CASE_INSENSITIVE);
private static final Pattern P_AJAX_PATH = Pattern.compile("(?:['\"/]|^)(ajax(?:m|file)\\.php\\?file=\\d+)");
private static final Pattern P_SIGN = Pattern.compile("'sign'\\s*:\\s*'([^']+)'");
private static final Pattern P_ISNGIS = Pattern.compile("var\\s+isngis\\s*=\\s*'([^']+)'");
@@ -259,18 +292,17 @@ public class LzTool extends PanBase {
return path.isEmpty() || "-".equals(path);
}
/** 统一改写到 {@link #SHARE_URL_PREFIX},只保留分享路径。 */
private String resolveShareUrl() {
String u = shareLinkInfo.getShareUrl();
/**
* 分享页 / 目录页 GET 保留原始主机和路径。
* 只有分享路径缺失(空链接、shareKey 占位)时才落到 {@link #SHARE_URL_PREFIX}。
*/
static String resolveSharePageUrl(String shareUrl, String standardUrl, String shareKey) {
String u = shareUrl;
if (isPlaceholderShare(u)) {
u = shareLinkInfo.getStandardUrl();
u = standardUrl;
}
if (isPlaceholderShare(u)) {
String key = shareLinkInfo.getShareKey();
if (key == null || key.isBlank() || "-".equals(key)) {
return SHARE_URL_PREFIX;
}
return SHARE_URL_PREFIX + key;
return canonicalShareUrl(shareKey, null);
}
int q = u.indexOf('?');
String query = null;
@@ -284,10 +316,167 @@ public class LzTool extends PanBase {
}
int pathStart = u.indexOf('/', schemeEnd + 3);
if (pathStart < 0) {
String key = shareLinkInfo.getShareKey();
return appendWebpage(SHARE_URL_PREFIX + (key == null ? "" : key), query);
String base = u.endsWith("/") ? u : u + "/";
if (shareKey == null || shareKey.isBlank() || "-".equals(shareKey)) {
return appendWebpage(base, query);
}
return appendWebpage(base + shareKey, query);
}
return appendWebpage(SHARE_ORIGIN + u.substring(pathStart), query);
return appendWebpage(u, query);
}
private String resolveShareUrl() {
return resolveSharePageUrl(
shareLinkInfo.getShareUrl(),
shareLinkInfo.getStandardUrl(),
shareLinkInfo.getShareKey());
}
/** 无原始主机时用标准下载域拼分享路径,不再写死 wwww.lanzoux.com。 */
private static String canonicalShareUrl(String shareKey, String query) {
if (shareKey == null || shareKey.isBlank() || "-".equals(shareKey)) {
return appendWebpage(SHARE_URL_PREFIX, query);
}
return appendWebpage(SHARE_URL_PREFIX + shareKey, query);
}
/**
* 目录内文件页主机:沿用已有分享主机,否则用 {@link #SHARE_URL_PREFIX}。
*/
static String sharePageHostBase(String shareUrl, String standardUrl) {
String u = !isPlaceholderShare(shareUrl) ? shareUrl : standardUrl;
if (!isPlaceholderShare(u)) {
String origin = normalizeOrigin(originOf(u, SHARE_ORIGIN));
return origin + "/";
}
return SHARE_URL_PREFIX;
}
/**
* 目录 filemore 的 POST 主机顺序:分享页源站优先(普通节点通常可用),
* 然后是稳定下载域。wwww.lanzoux.com 固定排在最后。
*/
static List<String> ajaxOrigins(String pageUrl) {
List<String> origins = new ArrayList<>();
addAjaxOrigin(origins, normalizeOrigin(originOf(pageUrl, "")));
for (String candidate : AJAX_FALLBACK_ORIGINS) {
addAjaxOrigin(origins, candidate);
}
return origins;
}
/**
* 文件 ajax 主机顺序。页面里若写出绝对 ajax URL,该主机最先尝试;
* 否则先打页面源站。空响应后再试 {@link #APIFILE_ORIGIN},四 w 仍在最后。
*
* @param ajaxTarget {@link #fileAjaxTarget} 的返回值,绝对 URL 或相对路径;可为 null
*/
static List<String> fileAjaxOrigins(String pageUrl, String ajaxTarget) {
List<String> origins = new ArrayList<>();
addAjaxOrigin(origins, originFromAjaxTarget(ajaxTarget));
addAjaxOrigin(origins, normalizeOrigin(originOf(pageUrl, "")));
for (String candidate : FILE_AJAX_FALLBACK_ORIGINS) {
addAjaxOrigin(origins, candidate);
}
return origins;
}
/**
* 从分享页或 iframe HTML 取出文件 ajax 地址。
* 绝对 URL(含协议相对 {@code //host/...})原样返回;否则返回以 {@code /} 开头的相对路径。
*/
static String fileAjaxTarget(String html) {
if (html == null || html.isEmpty()) {
return null;
}
Matcher abs = P_AJAX_ABSOLUTE.matcher(html);
if (abs.find()) {
String url = abs.group(1);
if (url.startsWith("//")) {
url = "https:" + url;
}
return url;
}
Matcher ajax = P_AJAX_PATH.matcher(html);
if (!ajax.find()) {
return null;
}
return "/" + ajax.group(1);
}
private static void addAjaxOrigin(List<String> origins, String origin) {
if (origin != null && origin.contains("://") && !origins.contains(origin)) {
origins.add(origin);
}
}
private static String originFromAjaxTarget(String ajaxTarget) {
if (ajaxTarget == null) {
return "";
}
if (ajaxTarget.startsWith("http://") || ajaxTarget.startsWith("https://")) {
return normalizeOrigin(originOf(ajaxTarget, ""));
}
return "";
}
private static String normalizeOrigin(String origin) {
if (origin == null) {
return "";
}
String o = origin.trim();
while (o.endsWith("/")) {
o = o.substring(0, o.length() - 1);
}
return o;
}
/**
* 个性域名常见 {@code inf=已超时},或响应根本不是 JSON。这类结果说明当前主机不可用,应换下一个域名。
* 密码错误、分享失效等业务错误不换域名。
*/
static boolean ajaxResponseShouldFallback(String text) {
if (text == null || text.isBlank()) {
return true;
}
JsonObject json = parseLzJson(text);
if (json == null) {
return true;
}
Integer zt = jsonInt(json, "zt");
if (zt != null && zt == 1) {
return false;
}
String info = ajaxInfoText(json);
return info != null && info.contains("超时");
}
private static Integer jsonInt(JsonObject json, String key) {
Object v = json.getValue(key);
if (v instanceof Number n) {
return n.intValue();
}
if (v instanceof CharSequence) {
try {
return Integer.parseInt(v.toString().trim());
} catch (NumberFormatException ignored) {
return null;
}
}
return null;
}
private static String ajaxInfoText(JsonObject json) {
for (String key : new String[]{"inf", "info"}) {
Object v = json.getValue(key);
if (v instanceof CharSequence) {
String s = v.toString().trim();
if (!s.isEmpty() && !"null".equalsIgnoreCase(s)) {
return s;
}
}
}
return null;
}
/** 目录文件 ID 可能带 webpage=,必须保留;pwd 走独立字段,不拼进 URL。 */
@@ -411,8 +600,12 @@ public class LzTool extends PanBase {
return true;
}
/** 页面里提取出的 ajax 调用:相对路径 + 表单参数。 */
private record AjaxCall(String path, Map<String, String> form) {
/** 页面里提取出的 ajax 调用。absoluteUrl 非空时优先打该主机。 */
private record AjaxCall(String path, Map<String, String> form, String absoluteUrl) {
private AjaxCall(String path, Map<String, String> form) {
this(path, form, null);
}
MultiMap toForm() {
MultiMap m = MultiMap.caseInsensitiveMultiMap();
form.forEach(m::set);
@@ -424,11 +617,12 @@ public class LzTool extends PanBase {
if (html == null || html.isEmpty()) {
return null;
}
Matcher ajax = P_AJAX_PATH.matcher(html);
if (!ajax.find()) {
String target = fileAjaxTarget(html);
if (target == null) {
return null;
}
String ajaxPath = ajax.group(1);
String absolute = target.startsWith("http://") || target.startsWith("https://") ? target : null;
String ajaxPath = absolute == null ? target : pathOfAbsolute(absolute);
Map<String, String> data = new LinkedHashMap<>();
data.put("action", "downprocess");
Matcher wp = P_WP_SIGN.matcher(html);
@@ -482,7 +676,23 @@ public class LzTool extends PanBase {
data.put("signs", ad2.group(1));
}
}
return new AjaxCall("/" + ajaxPath, data);
return new AjaxCall(ajaxPath, data, absolute);
}
private static String pathOfAbsolute(String url) {
try {
URL u = new URL(url);
String path = u.getPath() == null ? "" : u.getPath();
if (u.getQuery() != null && !u.getQuery().isEmpty()) {
path = path + "?" + u.getQuery();
}
if (!path.startsWith("/")) {
path = "/" + path;
}
return path;
} catch (Exception e) {
return url;
}
}
private static AjaxCall extractFolderAjax(String html, String pwd) {
@@ -576,12 +786,58 @@ public class LzTool extends PanBase {
private void getDownURL(String referer, AjaxCall call) {
MultiMap headers = HeaderUtils.parseHeaders(DOWN_AJAX_HEADERS);
// 个性域名 ajaxfile.php 会立刻 inf=已超时;POST 必须打 wwww。iframe 请求 Referer 用 iframe 地址。
headers.set("referer", referer != null && !referer.isBlank() ? referer : resolveShareUrl());
String url = joinUrl(SHARE_ORIGIN + "/", call.path());
// 文件 ajax 优先用页面里的绝对地址(常见 apifile.lanzouw.com)。
// 页面源站空响应再换 FILE_AJAX_FALLBACK_ORIGINS,wwww 仍在最后。
// iframe / 分享页的 Referer 保持原主机,不把页面 GET 改写到 wwww。
String page = referer != null && !referer.isBlank() ? referer : resolveShareUrl();
headers.set("referer", page);
String target = call.absoluteUrl() != null ? call.absoluteUrl() : call.path();
postAjaxAt(fileAjaxOrigins(page, target), 0, call, headers, this::handleAjaxDownResponse, null);
}
/**
* 依次向 {@link #ajaxOrigins} 发 POST。连接失败或「已超时」换下一个主机;
* wwww.lanzoux.com 只在最后尝试。业务错误(密码、失效)立即返回。
*/
private void postAjaxWithFallback(String pageUrl, AjaxCall call, MultiMap headers,
Handler<String> onBody, Handler<Throwable> onFailure) {
postAjaxAt(ajaxOrigins(pageUrl), 0, call, headers, onBody, onFailure);
}
private void postAjaxAt(List<String> origins, int index, AjaxCall call, MultiMap headers,
Handler<String> onBody, Handler<Throwable> onFailure) {
if (index >= origins.size()) {
String msg = "蓝奏 ajax 全部域名均失败";
if (onFailure != null) {
onFailure.handle(new RuntimeException(msg));
} else {
fail(msg);
}
return;
}
String url = joinUrl(origins.get(index) + "/", call.path());
boolean hasNext = index + 1 < origins.size();
postFormWithArg1Retry(url, headers, call.toForm())
.onSuccess(this::handleAjaxDownResponse)
.onFailure(handleFail(url));
.onSuccess(text -> {
if (hasNext && ajaxResponseShouldFallback(text)) {
log.warn("蓝奏 ajax {} 不可用,改试下一域名", url);
postAjaxAt(origins, index + 1, call, headers, onBody, onFailure);
return;
}
onBody.handle(text);
})
.onFailure(err -> {
if (hasNext) {
log.warn("蓝奏 ajax {} 请求失败: {},改试下一域名", url, err.getMessage());
postAjaxAt(origins, index + 1, call, headers, onBody, onFailure);
return;
}
if (onFailure != null) {
onFailure.handle(err);
} else {
handleFail(url).handle(err);
}
});
}
private void handleAjaxDownResponse(String text) {
@@ -913,10 +1169,9 @@ public class LzTool extends PanBase {
}
log.debug("解析参数: {}", call.form());
String url = joinUrl(originOf(sUrl, SHARE_ORIGIN) + "/", call.path());
postFormWithArg1Retry(url, folderListHeaders(sUrl), call.toForm())
.onSuccess(body -> handleFileListResponse(body, listPromise))
.onFailure(listPromise::fail);
postAjaxWithFallback(sUrl, call, folderListHeaders(sUrl),
body -> handleFileListResponse(body, listPromise),
listPromise::fail);
} catch (ScriptException | NoSuchMethodException | RuntimeException e) {
listPromise.fail(e);
}
@@ -1069,7 +1324,7 @@ public class LzTool extends PanBase {
if (webpage == null || webpage.isBlank()) {
webpage = extractWebpage(shareLinkInfo.getShareUrl(), null);
}
String fileUrl = SHARE_URL_PREFIX + id;
String fileUrl = sharePageHostBase(shareLinkInfo.getShareUrl(), shareLinkInfo.getStandardUrl()) + id;
if (webpage != null && !webpage.isBlank()) {
fileUrl = fileUrl + "?webpage=" + webpage;
}
@@ -3,6 +3,7 @@ package cn.qaiu.parser.impl;
import cn.qaiu.entity.FileInfo;
import cn.qaiu.entity.ShareLinkInfo;
import cn.qaiu.parser.PanBase;
import cn.qaiu.parser.PasswordLoginRisk;
import cn.qaiu.parser.TokenCache;
import cn.qaiu.util.CommonUtils;
import cn.qaiu.util.FileSizeConverter;
@@ -272,24 +273,27 @@ public class Ye2Tool extends PanBase {
.putHeader("platform", "web")
.sendJsonObject(loginBody)
.onSuccess(res -> {
JsonObject json = res.bodyAsJsonObject();
JsonObject json;
try {
json = res.bodyAsJsonObject();
} catch (Exception e) {
promise.fail(PasswordLoginRisk.nonJsonLoginFailure(res.bodyAsString()));
return;
}
if (json == null) {
promise.fail("登录响应格式异常: " + res.bodyAsString());
promise.fail(PasswordLoginRisk.nonJsonLoginFailure(res.bodyAsString()));
return;
}
if (!json.containsKey("code")) {
promise.fail("登录响应格式异常: " + res.bodyAsString());
return;
}
if (json.getInteger("code") != 200) {
promise.fail("登录失败: " + json.getString("message"));
// 验证码/风控只提示改用 Authorization,不求解、不重试。
if (!PasswordLoginRisk.isLoginSuccess(json)) {
promise.fail(PasswordLoginRisk.describeLoginFailure(json));
return;
}
JsonObject data = json.getJsonObject("data");
if (data == null || !data.containsKey("token")) {
promise.fail("未获取到token");
return;
}
String ssoToken = data.getString("token");
String expireStr = data.getString("expire");
long expireMs;
+50 -6
View File
@@ -55,8 +55,50 @@ def encode123(url, way, version, timestamp):
# 返回加密后的URL参数
return f"?{y}={time_long}-{a}-{final_crc}"
# 与 parser PasswordLoginRisk 保持一致:验证码/风控只提示改用 Authorization,不求解、不重试。
_RISK_KEYWORDS = (
"验证码", "风控", "安全风险", "安全验证", "安全校验", "滑块", "滑动验证",
"拼图验证", "短信验证", "微信登录", "微信进行登录", "境外登录", "需要验证", "请验证",
"请你验证", "进行验证", "完成验证", "二次验证", "人机验证", "操作频繁", "请求过于频繁",
"请求频繁", "captcha", "recaptcha", "risk control",
)
_AUTH_HINT = (
"账号密码登录触发了验证码/风控,已停止用户名密码登录(不会尝试验证码)。"
"请改为配置 Authorization(浏览器登录后的 Bearer token / JWT,"
"例如 localStorage 的 authorToken、请求头 authorization 或 Cookie 的 sso-token)。"
"静态配置写在 app-dev.yml 的 auths.ye.authorization(与 auths.ye.token 等价);"
"临时请求使用 authType=authorization 或 authType=accesstoken,token 填该令牌(不要重复带 Bearer 前缀)。"
"说明见 parser/doc/auth-param/。"
)
def format_login_failure(result):
"""把 123 登录失败响应转成用户可见说明。"""
if not isinstance(result, dict):
return "登录失败"
message = result.get("message") or result.get("msg") or ""
data = result.get("data") if isinstance(result.get("data"), dict) else {}
data_message = data.get("message") or data.get("msg") or ""
blob = f"{message} {data_message}".lower()
risk_field = any(
key.lower().find(flag) >= 0 and data.get(key) not in (None, False, 0, "", "false", "0")
for key in data
for flag in ("captcha", "vcode", "risk", "needverify", "need_verify", "slideverify", "verifycode", "verify_code")
)
if risk_field or any(keyword.lower() in blob for keyword in _RISK_KEYWORDS):
code = result.get("code")
upstream = message or data_message
extra = f"code={code}" if code is not None else ""
if upstream:
extra = f"{extra}, message={upstream}" if extra else f"message={upstream}"
return f"{_AUTH_HINT} 上游返回:{extra}" if extra else _AUTH_HINT
if result.get("code") == 200:
return "未获取到token"
return f"登录失败: {message}" if message else "登录失败"
def login_123pan(username, password):
"""登录123盘获取token"""
"""登录123盘获取token。成功返回 token,失败返回 None(错误已打印)。"""
print(f"🔐 正在登录账号: {username}")
login_data = {
@@ -73,16 +115,18 @@ def login_123pan(username, password):
)
result = response.json()
if result.get('code') == 200:
if result.get('code') == 200 and result.get('data', {}).get('token'):
token = result.get('data', {}).get('token', '')
print(f"✅ 登录成功!")
return token
else:
error_msg = result.get('message', '未知错误')
print(f"❌ 登录失败: {error_msg}")
error_msg = format_login_failure(result)
login_123pan.last_error = error_msg
print(f"❌ {error_msg}")
return None
except Exception as e:
print(f"❌ 登录请求失败: {e}")
login_123pan.last_error = f"登录请求失败: {e}"
print(f"❌ {login_123pan.last_error}")
return None
def get_share_info(share_key, password=''):
@@ -189,7 +233,7 @@ def start(link, password='', username='', user_password=''):
if not token:
return {
"code": 201,
"message": "登录失败"
"message": getattr(login_123pan, "last_error", None) or "登录失败"
}
else:
print("⚠️ 未提供登录信息,某些文件可能无法下载")
@@ -0,0 +1,115 @@
package cn.qaiu.parser;
import io.vertx.core.json.JsonObject;
import org.junit.Test;
import static org.junit.Assert.assertEquals;
import static org.junit.Assert.assertFalse;
import static org.junit.Assert.assertTrue;
public class PasswordLoginRiskTest {
@Test
public void securityRiskMessageGuidesAuthorization() {
JsonObject body = new JsonObject()
.put("code", 401)
.put("message", "当前账号存在安全风险,请使用短信验证码或者微信进行登录。");
assertTrue(PasswordLoginRisk.indicatesCaptchaOrRisk(body));
String message = PasswordLoginRisk.describeLoginFailure(body);
assertTrue(message.startsWith(PasswordLoginRisk.AUTHORIZATION_HINT));
assertTrue(message.contains("验证码/风控"));
assertTrue(message.contains("auths.ye.authorization"));
assertTrue(message.contains("authType=authorization"));
assertTrue(message.contains("authType=accesstoken"));
assertTrue(message.contains("code=401"));
assertTrue(message.contains("当前账号存在安全风险"));
assertFalse(message.startsWith("登录失败:"));
}
@Test
public void overseasRiskAndCaptchaPhrasesMatch() {
assertRisk("当前账号存在境外登录风险,请使用短信验证码或者微信进行登录。");
assertRisk("请完成安全验证");
assertRisk("请进行滑块验证");
assertRisk("操作频繁,请稍后再试");
assertRisk("captcha required");
}
@Test
public void wrongPasswordStaysDistinct() {
JsonObject body = new JsonObject()
.put("code", 500)
.put("message", "用户名或密码错误");
assertFalse(PasswordLoginRisk.indicatesCaptchaOrRisk(body));
assertEquals("登录失败: 用户名或密码错误", PasswordLoginRisk.describeLoginFailure(body));
JsonObject account = new JsonObject().put("code", 1).put("msg", "账号或密码错误");
assertFalse(PasswordLoginRisk.indicatesCaptchaOrRisk(account));
assertEquals("登录失败: 账号或密码错误", PasswordLoginRisk.describeLoginFailure(account));
}
@Test
public void riskFieldWithoutKeywordStillHints() {
JsonObject body = new JsonObject()
.put("code", 200)
.put("message", "ok")
.put("data", new JsonObject().put("needCaptcha", true));
assertFalse(PasswordLoginRisk.isLoginSuccess(body));
assertTrue(PasswordLoginRisk.indicatesCaptchaOrRisk(body));
assertTrue(PasswordLoginRisk.describeLoginFailure(body).contains("Authorization"));
}
@Test
public void falseCaptchaFlagDoesNotHint() {
JsonObject body = new JsonObject()
.put("code", 500)
.put("message", "用户名或密码错误")
.put("data", new JsonObject().put("needCaptcha", false));
assertFalse(PasswordLoginRisk.indicatesCaptchaOrRisk(body));
assertEquals("登录失败: 用户名或密码错误", PasswordLoginRisk.describeLoginFailure(body));
}
@Test
public void successTokenIsNotTreatedAsFailure() {
JsonObject body = new JsonObject()
.put("code", 200)
.put("message", "ok")
.put("data", new JsonObject().put("token", "jwt-token"));
assertTrue(PasswordLoginRisk.isLoginSuccess(body));
}
@Test
public void blankTokenWithoutRiskKeepsMissingTokenMessage() {
JsonObject body = new JsonObject()
.put("code", 200)
.put("message", "ok")
.put("data", new JsonObject().put("token", ""));
assertFalse(PasswordLoginRisk.isLoginSuccess(body));
assertEquals("未获取到token", PasswordLoginRisk.describeLoginFailure(body));
}
@Test
public void nonJsonCaptchaBodyUsesHint() {
String body = "<html>请完成滑块验证</html>";
String message = PasswordLoginRisk.nonJsonLoginFailure(body);
assertTrue(message.startsWith(PasswordLoginRisk.AUTHORIZATION_HINT));
}
@Test
public void nonJsonWrongPasswordStaysFormatError() {
assertEquals("登录响应格式异常: 用户名或密码错误",
PasswordLoginRisk.nonJsonLoginFailure("用户名或密码错误"));
}
private static void assertRisk(String message) {
JsonObject body = new JsonObject().put("code", 5202).put("message", message);
assertTrue(message, PasswordLoginRisk.indicatesCaptchaOrRisk(body));
assertTrue(PasswordLoginRisk.describeLoginFailure(body).startsWith(PasswordLoginRisk.AUTHORIZATION_HINT));
}
}
@@ -0,0 +1,178 @@
package cn.qaiu.parser.impl;
import org.junit.Test;
import java.util.List;
import static org.junit.Assert.assertEquals;
import static org.junit.Assert.assertFalse;
import static org.junit.Assert.assertTrue;
/**
* 个性域名 a.lanzouw.com 不能被改写到 wwww.lanzoux.com(四个 w)。
* 部分出口连不上四 w,页面请求会超时;ajax 只把四 w 当作最后兜底。
*/
public class LzToolShareUrlTest {
@Test
public void personalDomainPageStaysOffWwww() {
String resolved = LzTool.resolveSharePageUrl(
"https://a.lanzouw.com/xxx",
"https://w1.lanzn.com/xxx",
"xxx");
assertEquals("https://a.lanzouw.com/xxx", resolved);
assertFalse(resolved.contains("wwww.lanzoux.com"));
}
@Test
public void folderPageKeepsOriginalHost() {
String resolved = LzTool.resolveSharePageUrl(
"https://a.lanzouw.com/b710887",
"https://w1.lanzn.com/b710887",
"b710887");
assertEquals("https://a.lanzouw.com/b710887", resolved);
}
@Test
public void nodeShareIsNotRewrittenToWwww() {
String resolved = LzTool.resolveSharePageUrl(
"https://wwn.lanzouy.com/ihLkw1gezutg",
"https://w1.lanzn.com/ihLkw1gezutg",
"ihLkw1gezutg");
assertEquals("https://wwn.lanzouy.com/ihLkw1gezutg", resolved);
}
@Test
public void webpageQueryStaysOnOriginalHost() {
String resolved = LzTool.resolveSharePageUrl(
"https://a.lanzouw.com/iabc?webpage=wp1&pwd=secret",
"https://w1.lanzn.com/iabc",
"iabc");
assertEquals("https://a.lanzouw.com/iabc?webpage=wp1", resolved);
}
@Test
public void placeholderUsesStandardHostNotWwww() {
assertEquals("https://w1.lanzn.com/", LzTool.SHARE_URL_PREFIX);
assertFalse(LzTool.SHARE_URL_PREFIX.contains("wwww"));
String resolved = LzTool.resolveSharePageUrl(
"https://w1.lanzn.com/-",
"https://w1.lanzn.com/-",
"iFileId");
assertEquals("https://w1.lanzn.com/iFileId", resolved);
assertFalse(resolved.contains("wwww.lanzoux.com"));
}
@Test
public void missingShareUrlKeepsRealStandardHost() {
String resolved = LzTool.resolveSharePageUrl(
null,
"https://www.lanzoux.com/iabc",
"iabc");
assertEquals("https://www.lanzoux.com/iabc", resolved);
}
@Test
public void ajaxFallbackOrderPutsWwwwLast() {
List<String> fallback = LzTool.AJAX_FALLBACK_ORIGINS;
assertEquals("https://w1.lanzn.com", fallback.get(0));
assertEquals("https://www.lanzoux.com", fallback.get(1));
assertEquals("https://wwww.lanzoux.com", fallback.get(fallback.size() - 1));
List<String> origins = LzTool.ajaxOrigins("https://a.lanzouw.com/xxx");
assertEquals("https://a.lanzouw.com", origins.get(0));
assertEquals("https://w1.lanzn.com", origins.get(1));
assertEquals("https://www.lanzoux.com", origins.get(2));
assertEquals("https://wwww.lanzoux.com", origins.get(origins.size() - 1));
assertTrue(origins.indexOf("https://wwww.lanzoux.com")
> origins.indexOf("https://w1.lanzn.com"));
}
@Test
public void ajaxOriginsDoNotDuplicateKnownHost() {
List<String> origins = LzTool.ajaxOrigins("https://www.lanzoux.com/iabc");
assertEquals(3, origins.size());
assertEquals("https://www.lanzoux.com", origins.get(0));
assertEquals("https://w1.lanzn.com", origins.get(1));
assertEquals("https://wwww.lanzoux.com", origins.get(2));
}
@Test
public void timeoutAjaxFallsBackButBusinessErrorDoesNot() {
assertTrue(LzTool.ajaxResponseShouldFallback("{\"zt\":0,\"inf\":\"已超时\"}"));
assertTrue(LzTool.ajaxResponseShouldFallback("{\"info\":\"请求超时\"}"));
assertTrue(LzTool.ajaxResponseShouldFallback(""));
assertTrue(LzTool.ajaxResponseShouldFallback("<html>blocked</html>"));
assertFalse(LzTool.ajaxResponseShouldFallback("{\"zt\":0,\"inf\":\"密码错误\"}"));
assertFalse(LzTool.ajaxResponseShouldFallback(
"{\"zt\":1,\"inf\":\"name.zip\",\"dom\":\"https://x\",\"url\":\"abc\"}"));
}
@Test
public void filePagePrefersExistingHostOverWwww() {
assertEquals("https://a.lanzouw.com/",
LzTool.sharePageHostBase("https://a.lanzouw.com/b123", "https://w1.lanzn.com/b123"));
assertEquals("https://w1.lanzn.com/",
LzTool.sharePageHostBase("https://w1.lanzn.com/-", "https://w1.lanzn.com/-"));
assertFalse(LzTool.sharePageHostBase("https://a.lanzouw.com/b123", null).contains("wwww"));
}
@Test
public void absoluteAjaxUrlIsKeptAndTriedFirst() {
String html = """
url : 'https://apifile.lanzouw.com/ajaxfile.php?file=320665771',
data : { 'action':'downprocess','sign':isngis,'kd':kdns,'p':pwd, },
""";
String target = LzTool.fileAjaxTarget(html);
assertEquals("https://apifile.lanzouw.com/ajaxfile.php?file=320665771", target);
List<String> origins = LzTool.fileAjaxOrigins(
"https://wwaqg.lanzouu.com/iqouM49vy9ib", target);
assertEquals("https://apifile.lanzouw.com", origins.get(0));
assertTrue(origins.contains("https://wwaqg.lanzouu.com"));
assertEquals("https://wwww.lanzoux.com", origins.get(origins.size() - 1));
assertTrue(origins.indexOf("https://apifile.lanzouw.com")
< origins.indexOf("https://wwaqg.lanzouu.com"));
assertTrue(origins.indexOf("https://wwww.lanzoux.com")
> origins.indexOf("https://w1.lanzn.com"));
assertEquals(1, origins.stream().filter("https://apifile.lanzouw.com"::equals).count());
}
@Test
public void protocolRelativeAjaxBecomesHttps() {
String html = "url : '//apifile.lanzouw.com/ajaxfile.php?file=9',";
assertEquals("https://apifile.lanzouw.com/ajaxfile.php?file=9", LzTool.fileAjaxTarget(html));
}
@Test
public void absoluteAjaxWinsOverRelativePathInSamePage() {
String html = """
//data : { url : '/ajaxfile.php?file=1' }
url : "https://apifile.lanzouw.com/ajaxm.php?file=42",
""";
assertEquals("https://apifile.lanzouw.com/ajaxm.php?file=42", LzTool.fileAjaxTarget(html));
}
@Test
public void relativeFileAjaxFallsThroughToApifileBeforeWwww() {
String html = "url : '/ajaxfile.php?file=150233466',";
assertEquals("/ajaxfile.php?file=150233466", LzTool.fileAjaxTarget(html));
List<String> origins = LzTool.fileAjaxOrigins("https://a.lanzouw.com/xxx", LzTool.fileAjaxTarget(html));
assertEquals("https://a.lanzouw.com", origins.get(0));
assertEquals("https://apifile.lanzouw.com", origins.get(1));
assertEquals("https://wwww.lanzoux.com", origins.get(origins.size() - 1));
assertTrue(origins.indexOf("https://apifile.lanzouw.com")
< origins.indexOf("https://wwww.lanzoux.com"));
assertFalse(LzTool.ajaxOrigins("https://a.lanzouw.com/xxx").contains("https://apifile.lanzouw.com"));
}
@Test
public void missingAjaxTargetStillPutsApifileBeforeWwww() {
List<String> origins = LzTool.fileAjaxOrigins("https://www.lanzoux.com/ihLkw1gezutg", null);
assertEquals("https://www.lanzoux.com", origins.get(0));
assertEquals("https://apifile.lanzouw.com", origins.get(1));
assertEquals("https://wwww.lanzoux.com", origins.get(origins.size() - 1));
assertFalse(origins.get(0).contains("wwww"));
}
}
+1 -1
View File
@@ -17,7 +17,7 @@
</modules>
<properties>
<revision>0.4.6</revision>
<revision>0.4.7</revision>
<java.version>17</java.version>
<maven.compiler.source>17</maven.compiler.source>
<maven.compiler.target>17</maven.compiler.target>
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "nfd-web",
"version": "0.4.6",
"version": "0.4.7",
"private": true,
"scripts": {
"serve": "vue-cli-service serve",