fix authorized remote message reads
Build web service image / build (push) Successful in 48s

This commit is contained in:
2026-09-21 11:18:09 +08:00
parent f8290a65bc
commit ab9ff389f2
7 changed files with 245 additions and 61 deletions
+120 -7
View File
@@ -379,23 +379,33 @@ internal static class ServiceSettingsEditor
throw new InvalidDataException("ListenUrl is invalid.");
static string? Optional(TextBox box) => string.IsNullOrWhiteSpace(box.Text) ? null : box.Text.Trim();
static string[] Lines(TextBox box) => box.Lines
.Select(line => line.Trim())
.Where(line => line.Length > 0)
.Distinct(StringComparer.Ordinal)
.ToArray();
var host = uri.Host.Trim('[', ']');
var token = current.AccessToken ?? ServiceOptions.GenerateToken();
var remote = current.Remote;
var reporting = (current.Reporting ?? new ReportingConfig()).NormalizeAndValidate();
var reportingAccount = reporting.Accounts.FirstOrDefault();
var boundAccounts = new AccountBindingStore(current).ReadAll();
var reportingAccountId = reportingAccount?.AccountId
?? (boundAccounts.Count == 1 ? boundAccounts[0].AccountId : "");
ServiceOptions? result = null;
using var form = new Form
{
Text = "WxAgent 服务设置",
Width = 720,
Height = 535,
Height = 805,
StartPosition = FormStartPosition.CenterScreen,
MinimizeBox = false,
MaximizeBox = false,
FormBorderStyle = FormBorderStyle.FixedDialog
};
var tabs = new TabControl { Left = 12, Top = 12, Width = 680, Height = 450 };
var tabs = new TabControl { Left = 12, Top = 12, Width = 680, Height = 720 };
var localTab = new TabPage("本地服务");
var remoteTab = new TabPage("远程连接");
tabs.TabPages.Add(localTab);
@@ -477,24 +487,84 @@ internal static class ServiceSettingsEditor
Left = 18, Top = 372, Width = 620, Height = 40,
Text = "控制面令牌与控制面 WXAGENT_NODE_TOKEN 一致;HTTP 仅允许私有 IP,公网或域名请使用 HTTPS。"
};
var reportingTitle = new Label
{
Left = 18, Top = 416, Width = 620, Height = 24,
Text = "远程读取白名单(不填写不会默认放行)"
};
var reportingEnabled = new CheckBox
{
Left = 18, Top = 442, Width = 620,
Text = "启用 Reporting 数据读取",
Checked = reporting.Enabled
};
var reportingAccountEnabled = new CheckBox
{
Left = 150, Top = 470, Width = 485,
Text = "启用当前账号",
Checked = reportingAccount?.Enabled ?? true
};
var reportingAccountLabel = new Label { Left = 18, Top = 505, Width = 125, Text = "账号 ID" };
var reportingAccountBox = new TextBox { Left = 150, Top = 501, Width = 485, Text = reportingAccountId };
var groupChatsLabel = new Label { Left = 18, Top = 541, Width = 125, Text = "群聊白名单" };
var groupChatsBox = new TextBox
{
Left = 150, Top = 537, Width = 485, Height = 48,
Multiline = true, AcceptsReturn = true, ScrollBars = ScrollBars.Vertical,
Text = string.Join(Environment.NewLine, reportingAccount?.AllowedChats
.Where(chat => chat.Type == ReportingChatType.Group).Select(chat => chat.ChatId) ?? [])
};
var privateChatsLabel = new Label { Left = 18, Top = 593, Width = 125, Text = "私聊白名单" };
var privateChatsBox = new TextBox
{
Left = 150, Top = 589, Width = 485, Height = 48,
Multiline = true, AcceptsReturn = true, ScrollBars = ScrollBars.Vertical,
Text = string.Join(Environment.NewLine, reportingAccount?.AllowedChats
.Where(chat => chat.Type == ReportingChatType.Private).Select(chat => chat.ChatId) ?? [])
};
var reportingIdentityConfirmed = new CheckBox
{
Left = 150, Top = 645, Width = 485,
Text = "确认上述 chatId 已与微信身份核对",
Checked = reportingAccount is not null && reportingAccount.AllowedChats.Count > 0 && reportingAccount.AllowedChats.All(chat => chat.IdentityVerified)
};
var reportingNote = new Label
{
Left = 18, Top = 674, Width = 620, Height = 36,
Text = "每行一个 chatId;通讯录/会话读取只返回白名单范围。"
};
remoteTab.Controls.AddRange([
remoteEnabled, remoteAddressLabel, remoteAddressBox, remoteNodeLabel, remoteNodeBox,
remoteAccountLabel, remoteAccountBox, remoteTokenLabel, remoteTokenBox,
remoteTokenFileLabel, remoteTokenFileBox, allowInsecureHttp, remoteServerCaLabel,
remoteServerCaBox, remoteClientCertLabel, remoteClientCertBox, remoteClientKeyLabel,
remoteClientKeyBox, remoteNote
remoteClientKeyBox, remoteNote, reportingTitle, reportingEnabled, reportingAccountEnabled,
reportingAccountLabel, reportingAccountBox, groupChatsLabel, groupChatsBox,
privateChatsLabel, privateChatsBox, reportingIdentityConfirmed, reportingNote
]);
var remoteInputs = new Control[]
{
remoteAddressBox, remoteNodeBox, remoteAccountBox, remoteTokenBox, remoteTokenFileBox,
allowInsecureHttp, remoteServerCaBox, remoteClientCertBox, remoteClientKeyBox
};
void SetRemoteEnabled() { foreach (var control in remoteInputs) control.Enabled = remoteEnabled.Checked; }
var reportingInputs = new Control[]
{
reportingAccountEnabled, reportingAccountBox, groupChatsBox, privateChatsBox,
reportingIdentityConfirmed
};
void SetRemoteEnabled()
{
foreach (var control in remoteInputs) control.Enabled = remoteEnabled.Checked;
reportingEnabled.Enabled = remoteEnabled.Checked;
var reportingInputsEnabled = remoteEnabled.Checked && reportingEnabled.Checked;
foreach (var control in reportingInputs) control.Enabled = reportingInputsEnabled;
}
remoteEnabled.CheckedChanged += (_, _) => SetRemoteEnabled();
reportingEnabled.CheckedChanged += (_, _) => SetRemoteEnabled();
SetRemoteEnabled();
var save = new Button { Left = 470, Top = 470, Width = 105, Text = "保存" };
var cancel = new Button { Left = 585, Top = 470, Width = 105, Text = "取消" };
var save = new Button { Left = 470, Top = 740, Width = 105, Text = "保存" };
var cancel = new Button { Left = 585, Top = 740, Width = 105, Text = "取消" };
copy.Click += (_, _) => { Clipboard.SetText(tokenBox.Text); copy.Text = "已复制"; };
regenerate.Click += (_, _) =>
{
@@ -525,6 +595,49 @@ internal static class ServiceSettingsEditor
AllowInsecureHttp = allowInsecureHttp.Checked
}
: null;
var reportingOptions = reporting;
if (remoteEnabled.Checked && reportingEnabled.Checked)
{
var accountId = Optional(reportingAccountBox);
if (accountId is null)
{
MessageBox.Show("启用 Reporting 时必须填写账号 ID。", "WxAgent 设置无效", MessageBoxButtons.OK, MessageBoxIcon.Warning);
return;
}
var allowedChats = Lines(groupChatsBox).Select(chatId => new AllowedChat
{
Type = ReportingChatType.Group,
ChatId = chatId,
Enabled = true,
IdentityVerified = reportingIdentityConfirmed.Checked
}).Concat(Lines(privateChatsBox).Select(chatId => new AllowedChat
{
Type = ReportingChatType.Private,
ChatId = chatId,
Enabled = true,
IdentityVerified = reportingIdentityConfirmed.Checked
})).ToArray();
var account = new AccountReportingConfig
{
AccountId = accountId,
Enabled = reportingAccountEnabled.Checked,
AllowedChats = allowedChats
};
var accounts = reporting.Accounts
.Where(existing => !string.Equals(existing.AccountId, accountId, StringComparison.Ordinal))
.Append(account)
.ToArray();
reportingOptions = reporting with
{
Enabled = true,
ConfigVersion = checked(reporting.ConfigVersion + 1),
Accounts = accounts
};
}
else if (remoteEnabled.Checked && !reportingEnabled.Checked)
{
reportingOptions = reporting with { Enabled = false };
}
var edited = new ServiceOptions
{
ListenUrl = $"http://{formattedHost}:{portBox.Value}",
@@ -535,7 +648,7 @@ internal static class ServiceSettingsEditor
CredentialFile = current.CredentialFile,
DataDirectory = current.DataDirectory,
Remote = remoteOptions,
Reporting = current.Reporting,
Reporting = reportingOptions,
RemoteConfigurationFile = null,
EnableValidationOperations = validation.Checked,
EnableListenerEvents = listenerEvents.Checked,