alist/internal
千石 c64f899a63
feat: implement session management (#9286)
* feat(auth): Added device session management

- Added the `handleSession` function to manage user device sessions and verify client identity
- Updated `auth.go` to call `handleSession` for device handling when a user logs in
- Added the `Session` model to database migrations
- Added `device.go` and `session.go` files to handle device session logic
- Updated `settings.go` to add device-related configuration items, such as the maximum number of devices, device eviction policy, and session TTL

* feat(session): Adds session management features

- Added `SessionInactive` error type in `device.go`
- Added session-related APIs in `router.go` to support listing and evicting sessions
- Added `ListSessionsByUser`, `ListSessions`, and `MarkInactive` methods in `session.go`
- Returns an appropriate error when the session state is `SessionInactive`

* feat(auth): Marks the device session as invalid.

- Import the `session` package into the `auth` module to handle device session status.
- Add a check in the login logic. If `device_key` is obtained, call `session.MarkInactive` to mark the device session as invalid.
- Store the invalid status in the context variable `session_inactive` for subsequent middleware checks.
- Add a check in the session refresh logic to abort the process if the current session has been marked invalid.

* feat(auth, session): Added device information processing and session management changes

- Updated device handling logic in `auth.go` to pass user agent and IP information
- Adjusted database queries in `session.go` to optimize session query fields and add `user_agent` and `ip` fields
- Modified the `Handle` method to add `ua` and `ip` parameters to store the user agent and IP address
- Added the `SessionResp` structure to return a session response containing `user_agent` and `ip`
- Updated the `/admin/user/create` and `/webdav` endpoints to pass the user agent and IP address to the device handler
2025-08-25 19:46:38 +08:00
..
archive perf: optimize IO read/write usage (#8243) 2025-04-12 16:55:31 +08:00
authn fix(authn): subfolder api is considered as a wrong origin(closes #6294 in #6301) 2024-04-03 14:33:19 +08:00
bootstrap feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
conf feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
db feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
device feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
driver feat(archive): support multipart archives (#8184 close #8015) 2025-03-27 23:20:44 +08:00
errs feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
fs feat: enhance permission control and label management (#9215) 2025-07-26 09:51:59 +08:00
fuse chore: add fuse package 2022-07-20 00:39:20 +08:00
message chore: change message type 2022-08-14 03:05:30 +08:00
model feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
net fix(net): unexpected write (#8291 close #8281) 2025-04-12 17:01:52 +08:00
offline_download feat(alias): support writing to non-ambiguous paths (#8216) 2025-03-27 23:17:45 +08:00
op fix: ensure DefaultRole stores role ID while exposing role name in APIs (#9279) 2025-08-19 15:01:32 +08:00
search fix(index): fix the issue where ignored paths are not updated (#7907) 2025-02-09 18:31:43 +08:00
session feat: implement session management (#9286) 2025-08-25 19:46:38 +08:00
setting refactor: split the db package hook and cache to the op package (#2747) 2022-12-18 19:51:20 +08:00
sign fix(archive): use another sign for extraction (#7982) 2025-03-01 18:34:33 +08:00
stream perf: optimize IO read/write usage (#8243) 2025-04-12 16:55:31 +08:00
task feat(task): allow retry canceled (#7852) 2025-01-27 20:18:10 +08:00