fix: authorize verified offline data sync
Build web service image / build (push) Successful in 1m6s

This commit is contained in:
2026-09-30 13:30:48 +08:00
parent edba7d0d38
commit e8abb15f68
12 changed files with 218 additions and 22 deletions
@@ -880,23 +880,18 @@ public sealed class RemoteAgentHostedService(
var wechatRunning = GetBoolean(element, "wechatAvailable");
var sessionAvailable = GetBoolean(element, "sessionAvailable");
var sessionLocked = GetBoolean(element, "sessionLocked");
// Heartbeats must not refresh UI identity. Binding already contains the verified identity;
// the explicit accounts API remains the only path that may inspect the profile.
// A persisted binding plus a key-verified database identity may authorize read-only sync.
// UI tasks still require a live, available WeChat session and a live window binding.
var accounts = await backend.AccountsAsync(cancellationToken, refreshUiIdentity: false);
var identities = accounts.Select(account => new RemoteAccountIdentity(
account.AccountId, HasLiveWeChatBinding(account))).ToArray();
var activeAccountId = remote.ActiveAccountId;
var boundAccounts = identities
.Where(identity => identity.Verified)
.Select(identity => identity.AccountId)
.Distinct(StringComparer.OrdinalIgnoreCase)
account.AccountId, HasLiveWeChatBinding(account) || account.IsVerifiedForReadOnlySync)).ToArray();
var liveBoundAccountIds = accounts
.Where(HasLiveWeChatBinding)
.Select(account => account.AccountId)
.ToArray();
if ((string.IsNullOrWhiteSpace(activeAccountId) || !identities.Any(identity => identity.Verified && string.Equals(identity.AccountId, activeAccountId, StringComparison.Ordinal)))
&& boundAccounts.Length == 1)
{
// A single verified binding is safe to use when the optional GUI value is empty or a display name.
activeAccountId = boundAccounts[0];
}
var hasLiveUiSession = wechatRunning && sessionAvailable && !sessionLocked;
var activeAccountId = RemoteAccountContext.SelectActiveAccountId(
hasLiveUiSession, remote.ActiveAccountId, identities, liveBoundAccountIds);
var activeAccountVerified = false;
if (activeAccountId is { Length: > 0 })
{
@@ -904,9 +899,15 @@ public sealed class RemoteAgentHostedService(
{
accountContext.SwitchTo(activeAccountId, identities);
activeAccountVerified = accountContext.IsConfirmedFor(activeAccountId);
if (!activeAccountVerified)
{
activeAccountId = null;
accountContext.Invalidate();
}
}
catch (WxAgentException)
{
activeAccountId = null;
accountContext.Invalidate();
}
}
@@ -923,7 +924,7 @@ public sealed class RemoteAgentHostedService(
}
catch
{
return new BackendSnapshot(RemoteNodeStatus.Degraded, false, false, false, remote.ActiveAccountId, 0, false, []);
return new BackendSnapshot(RemoteNodeStatus.Degraded, false, false, false, null, 0, false, []);
}
}