feat(auth): API 令牌 + 设备码授权登录 + pm CLI 骨架 - #63
Merged
Merged
Conversation
登录/权限系统升级(单用户 + API 令牌模型):
后端
- api_tokens / device_auth_requests 表 + alembic 迁移;令牌 SHA-256 哈希存储
- /auth/me、/auth/tokens(创建/列表/吊销,仅网页会话)、/auth/device/{start,poll,authorize,deny}
- AuthMiddleware 支持 pmt_ API 令牌:GET→read、变更→write scope 强制,last_used 节流
- 令牌可吊销自己(pm logout),管理他人令牌仅限 JWT
- MCP /mcp 换 DB 令牌验证器(fastmcp TokenVerifier),保留静态 MCP_AUTH_TOKEN 应急
- PG 启动时自动 alembic upgrade head,auto_deploy 合并即上线
前端
- 设置页新增「API 令牌」tab(创建/明文一次性展示/吊销)
- /device 设备码授权页(未登录内嵌登录,批准/拒绝)
CLI(pm)
- pm login 设备码流程 + --token 粘贴兜底、logout(自吊销)、whoami、doctor
- 配置 ~/.config/papermind/config.toml(0600),env PAPERMIND_SERVER_URL/TOKEN 优先
- [project.scripts] pm = apps.cli.main:app
测试:tests/test_auth_tokens.py 13 例(令牌生命周期/scope/设备流程/中间件),全量 82 passed
🔍 OpenCode PR Review Required这是一个受保护的分支,merge 前需要进行 code review。 请运行以下命令进行 OpenCode review: 或者在 PR 页面评论 This is an automated reminder from PR Review Gate. |
- apps/cli/__main__.py:PyInstaller / python -m apps.cli 双用入口 - .github/workflows/pm-cli-release.yml:四平台矩阵构建 (darwin-arm64 / darwin-x86_64 / linux-x86_64 / windows-x86_64), tag pm-v* 触发发布 GitHub Release,workflow_dispatch 手动构建 - scripts/build-pm-cli.sh:本地一条命令构建(CLI 只依赖 typer+httpx,产物约 13MB) - scripts/install-pm.sh / install-pm.ps1:一键安装(下载最新 Release 到 PATH, macOS 自动去 quarantine),支持 curl|bash / irm|iex - README 安装章节改为免 Python 下载安装
🔍 OpenCode PR Review Required这是一个受保护的分支,merge 前需要进行 code review。 请运行以下命令进行 OpenCode review: 或者在 PR 页面评论 This is an automated reminder from PR Review Gate. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概述
登录/权限系统升级(单用户 + API 令牌模型),为 pm CLI / Claude Code / ZCode 等 harness 接入打地基。
服务端
api_tokens(SHA-256 哈希存储、read/write scope、有效期、last_used、可吊销)+device_auth_requests(设备码授权状态机)GET /auth/me、POST/GET/DELETE /auth/tokens(仅网页会话)、POST /auth/device/start|poll(无鉴权+白名单)、GET /auth/device/{user_code}、POST /auth/device/{user_code}/authorize|deny(仅网页会话)AuthMiddleware支持pmt_API 令牌:GET→read、变更→writescope 按 HTTP 方法强制;令牌可吊销自己(pm logout),管理他人令牌仅限 JWT/mcp换用 DB 令牌验证器(fastmcpTokenVerifier扩展点),保留静态MCP_AUTH_TOKEN应急回落alembic upgrade head,配合 auto_deploy 合并即上线建表前端
/device设备码授权页:深链放行登录门,未登录内嵌登录组件,确认设备码 → 批准/拒绝pm CLI(
apps/cli)pm login:设备码授权流程(打开浏览器 → 轮询 → 签发令牌),--token粘贴兜底pm logout(吊销自己 + 清配置)、pm whoami、pm doctor~/.config/papermind/config.toml(0600),envPAPERMIND_SERVER_URL/PAPERMIND_TOKEN优先[project.scripts] pm = apps.cli.main:app,pipx install /path/to/PaperMind即可装机测试
tests/test_auth_tokens.py13 例:令牌生命周期/scope 强制/过期吊销/设备流程全链路/中间件 401·403合并后
pipx install+pm login即接入;网页「设置 → API 令牌」可随时管理/吊销