Skip to content

feat: 数据源口令传输改为固定 AES,禁止明文 password - #899

Merged
LordofAvernus merged 3 commits into
mainfrom
dms-ui/feat-994
Sep 29, 2026
Merged

LordofAvernus merged 3 commits into
mainfrom
dms-ui/feat-994

Conversation

@LordofAvernus

@LordofAvernus LordofAvernus commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

关联的 issue

https://github.com/actiontech/dms-ee/issues/994

描述你的变更

  • 数据源测连通、创建、更新口令改为页内 AES-256-CBC 后只提交 secret_password,不再提交明文 password
  • 加密写在页面脚本里,HTTP 非 localhost 也不依赖 crypto.subtle,不新增 npm 包
  • 密钥、IV、PKCS7、Base64 与后端 SecretKey 一致;加密失败时中止提交,不回退明文

确认项(pr提交后操作)

Tip

请在指定复审人之前,确认并完成以下事项,完成后✅


  • 我已完成自测
  • 我已记录完整日志方便进行诊断
  • 我已在关联的issue里补充了实现方案
  • 我已在关联的issue里补充了测试影响面
  • 我已确认了变更的兼容性,如果不兼容则在issue里标记 not_compatible
  • 我已确认了是否要更新文档,如果要更新则在issue里标记 need_update_doc

Encrypt outbound DB passwords with the compile-time AES key into
secret_password so pages stop sending plaintext password fields.
Wire connectable check, add, and update flows to encrypt passwords locally,
update API typings/locale, and cover the outbound contract in page tests.
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 80.57% 30421/37755
🟡 Branches 62.8% 11432/18204
🟢 Functions 83.97% 10199/12146
🟢 Lines 84.39% 29070/34449

Test suite run success

3780 tests passing in 827 suites.

Report generated by 🧪jest coverage report action from 0464a01

Replace crypto.subtle so HTTP (non-secure context) can encrypt outbound
secret_password with the same fixed key/IV/PKCS7 wire format as backend.

Co-authored-by: Cursor <cursoragent@cursor.com>
@LordofAvernus
LordofAvernus merged commit 91cfd0e into main Sep 29, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant