文件
hulai-website/server/api/admin/login.post.js
T
Mimingguang和Claude Opus 4.6 ee078b61bc feat: 后台管理系统完整重构 + 前后台数据联通
- 后台全面引入 Naive UI 组件库,统一 UI 规范
- 前台 usePublicApi 切换到 API 调用(GET /api/content/[key])
- 前后台数据源统一(site_content 表)
- 产品线统一管理(tour/camp/course 三套编辑器)
- 产品数据归一化(itinerary/faq/pricing 格式统一)
- 表单提交 API 改写入 submissions 表
- 新增 submissions 标记已读 API
- site-content PUT 支持 upsert
- 修复前台 bug(stories 路由冲突、占位符警告、selector breadcrumb)
- 消除 PageHero 类型警告(useSEO reactive 修复)
- 25 个前台页面全部 HTTP 200,展示效果不变

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-24 17:48:02 +08:00

52 行
1.7 KiB
JavaScript

import { eq } from 'drizzle-orm'
import { useDB, schema } from '../../utils/db.js'
import { hashPassword, createSession } from '../../utils/auth.js'
// 简单的登录频率限制
const loginAttempts = new Map()
const MAX_ATTEMPTS = 5
const LOCK_TIME = 15 * 60 * 1000 // 15 分钟
export default defineEventHandler(async (event) => {
const ip = getRequestIP(event, { xForwardedFor: true }) ?? 'unknown'
// 检查频率限制
const record = loginAttempts.get(ip)
if (record && record.count >= MAX_ATTEMPTS && Date.now() - record.firstAt < LOCK_TIME) {
const waitMin = Math.ceil((LOCK_TIME - (Date.now() - record.firstAt)) / 60000)
throw createError({ statusCode: 429, message: `登录尝试过多,请 ${waitMin} 分钟后再试` })
}
const body = await readBody(event)
const { username, password } = body || {}
if (!username || !password) {
throw createError({ statusCode: 422, message: '请输入用户名和密码' })
}
const db = useDB()
const user = db
.select()
.from(schema.adminUsers)
.where(eq(schema.adminUsers.username, username))
.get()
if (!user || user.passwordHash !== hashPassword(password)) {
// 记录失败次数
const current = loginAttempts.get(ip) || { count: 0, firstAt: Date.now() }
if (Date.now() - current.firstAt > LOCK_TIME) {
loginAttempts.set(ip, { count: 1, firstAt: Date.now() })
} else {
current.count++
loginAttempts.set(ip, current)
}
throw createError({ statusCode: 401, message: '用户名或密码错误' })
}
// 登录成功,清除计数
loginAttempts.delete(ip)
const token = createSession(user.id)
return { success: true, token, username: user.username }
})