feat: 维护页 Tailscale 管理(设备列表/改名/授权/密钥不过期/设置IP/auth key,独立模块 core/tailscale_client.py)+ 密钥迁移 .env(STF_TOKEN/WEB_SECRET_KEY/TAILSCALE_API_KEY 不再入库)+ 修复设备更新端点(/device/{id} 405,改用 /name /authorized /key 专属端点)+ auth key description 仅 ASCII
This commit is contained in:
+104
-4
@@ -20,6 +20,7 @@ import atexit
|
||||
import secrets
|
||||
import functools
|
||||
import shlex
|
||||
import re
|
||||
import subprocess
|
||||
from datetime import datetime
|
||||
|
||||
@@ -35,16 +36,19 @@ from core.logger import get_logger, _LOG_DIR, _MODULE_FILES
|
||||
from core.models import db, init_db, User, DeviceGroup, TaskJob, CustomAction
|
||||
from core.apk_manager import ApkManager
|
||||
from core.adb_helper import screenshot, list_installed_apps, adb_connect_light, _ADB_LOCK, _adb
|
||||
from core import uiauto_helper
|
||||
from core import uiauto_helper, tailscale_client
|
||||
from core.tailscale_client import TailscaleError
|
||||
from config import ADB_PATH, STF_SSH_TARGET, STF_DOCKER_CONTAINER
|
||||
from tasks import list_task_types, get_task_class
|
||||
|
||||
_log = get_logger("web")
|
||||
|
||||
app = Flask(__name__)
|
||||
# 生产必须通过环境变量 WEB_SECRET_KEY 设置强密钥;缺省用开发密钥(不安全)
|
||||
app.config["SECRET_KEY"] = os.environ.get(
|
||||
"WEB_SECRET_KEY", "dev-secret-key-change-in-production")
|
||||
# 会话密钥:优先 .env 的 WEB_SECRET_KEY;未配置则随机生成(重启后登录态失效,生产务必配置固定值)
|
||||
_web_secret = os.environ.get("WEB_SECRET_KEY") or secrets.token_hex(32)
|
||||
if not os.environ.get("WEB_SECRET_KEY"):
|
||||
_log.warning("未配置 WEB_SECRET_KEY,已随机生成会话密钥(重启后登录态失效)")
|
||||
app.config["SECRET_KEY"] = _web_secret
|
||||
app.config["SQLALCHEMY_DATABASE_URI"] = "sqlite:///" + os.path.join(
|
||||
os.path.dirname(os.path.abspath(__file__)), "data", "users.db")
|
||||
app.config["SQLALCHEMY_TRACK_MODIFICATIONS"] = False
|
||||
@@ -976,6 +980,102 @@ def api_stf_restart():
|
||||
"detail": out.strip(), "api_alive": alive})
|
||||
|
||||
|
||||
# ================== API:Tailscale 管理(仅管理员) ==================
|
||||
# 通过 Tailscale 官方 API v2 管理 tailnet 设备(列表/改名/授权/密钥不过期/删除/生成 auth key)。
|
||||
# 设备 IP 由 tailnet 自动分配,API 无法修改,列表只读展示。
|
||||
|
||||
|
||||
@app.route("/api/tailscale/status")
|
||||
@admin_required
|
||||
def api_tailscale_status():
|
||||
"""Tailscale 管理配置状态(API key / tailnet 是否已配置)。"""
|
||||
c = tailscale_client.tailscale
|
||||
return jsonify({"ok": True, "configured": c.is_configured(),
|
||||
"hint": c.config_hint() if not c.is_configured() else ""})
|
||||
|
||||
|
||||
@app.route("/api/tailscale/devices")
|
||||
@admin_required
|
||||
def api_tailscale_devices():
|
||||
"""列出 tailnet 全部设备。"""
|
||||
try:
|
||||
return jsonify({"ok": True, "devices": tailscale_client.tailscale.list_devices()})
|
||||
except TailscaleError as e:
|
||||
return jsonify({"ok": False, "error": str(e)}), 502
|
||||
|
||||
|
||||
@app.route("/api/tailscale/devices/<device_id>", methods=["POST"])
|
||||
@admin_required
|
||||
def api_tailscale_device_update(device_id):
|
||||
"""更新设备:按传入字段分发到专属端点(改名 /name、授权 /authorized、密钥 /key)。"""
|
||||
data = request.json or {}
|
||||
c = tailscale_client.tailscale
|
||||
try:
|
||||
if "name" in data:
|
||||
c.set_device_name(device_id, data.get("name"))
|
||||
if "authorized" in data:
|
||||
c.set_device_authorized(device_id, data.get("authorized"))
|
||||
if "key_expiry_disabled" in data:
|
||||
c.set_device_key_expiry(device_id, data.get("key_expiry_disabled"))
|
||||
_log.info(f"Tailscale 设备更新 {device_id}: {data}")
|
||||
return jsonify({"ok": True, "msg": "设备已更新"})
|
||||
except TailscaleError as e:
|
||||
return jsonify({"ok": False, "error": str(e)}), 502
|
||||
|
||||
|
||||
@app.route("/api/tailscale/devices/<device_id>/ip", methods=["POST"])
|
||||
@admin_required
|
||||
def api_tailscale_device_ip(device_id):
|
||||
"""设置设备 IPv4 地址(未公开端点,实测可用)。
|
||||
|
||||
⚠ 改 IP 会断开设备当前 tailscale 会话,且平台设备池 serial 随之变化,
|
||||
改完需同步更新 STF 设备池(分组/任务目标里的旧 IP 会失效)。
|
||||
"""
|
||||
data = request.json or {}
|
||||
ipv4 = (data.get("ipv4") or "").strip()
|
||||
if not ipv4:
|
||||
return jsonify({"ok": False, "error": "缺少 ipv4"}), 400
|
||||
try:
|
||||
tailscale_client.tailscale.set_device_ip(device_id, ipv4)
|
||||
_log.info(f"Tailscale 设备 {device_id} IP 已设置为 {ipv4}")
|
||||
return jsonify({"ok": True, "msg": f"设备 IP 已设置为 {ipv4}"})
|
||||
except TailscaleError as e:
|
||||
return jsonify({"ok": False, "error": str(e)}), 502
|
||||
|
||||
|
||||
@app.route("/api/tailscale/devices/<device_id>", methods=["DELETE"])
|
||||
@admin_required
|
||||
def api_tailscale_device_delete(device_id):
|
||||
"""从 tailnet 移除设备。"""
|
||||
try:
|
||||
tailscale_client.tailscale.delete_device(device_id)
|
||||
_log.info(f"Tailscale 设备已移除: {device_id}")
|
||||
return jsonify({"ok": True, "msg": "设备已从 tailnet 移除"})
|
||||
except TailscaleError as e:
|
||||
return jsonify({"ok": False, "error": str(e)}), 502
|
||||
|
||||
|
||||
@app.route("/api/tailscale/authkey", methods=["POST"])
|
||||
@admin_required
|
||||
def api_tailscale_authkey():
|
||||
"""生成设备接入 auth key(key 只显示一次)。"""
|
||||
data = request.json or {}
|
||||
try:
|
||||
# Tailscale 要求 description 仅 ASCII(中文会 400)
|
||||
desc = re.sub(r"[^\x20-\x7e]", "", (data.get("description") or "").strip())
|
||||
key = tailscale_client.tailscale.create_auth_key(
|
||||
description=desc or "auto_control",
|
||||
reusable=bool(data.get("reusable", False)),
|
||||
ephemeral=bool(data.get("ephemeral", False)),
|
||||
preauthorized=data.get("preauthorized", True),
|
||||
expiry_seconds=int(data.get("expiry_seconds", 3600)))
|
||||
_log.info(f"Tailscale auth key 已生成: {key['id']}")
|
||||
return jsonify({"ok": True, "key": key["key"], "id": key["id"],
|
||||
"expires": key["expires"]})
|
||||
except TailscaleError as e:
|
||||
return jsonify({"ok": False, "error": str(e)}), 502
|
||||
|
||||
|
||||
# ================== uiautodev 自动启动 ==================
|
||||
_uiauto_proc = None
|
||||
# PID 文件:web_server 异常退出(kill -9/崩溃)时 uiautodev 成孤儿残留,
|
||||
|
||||
Reference in New Issue
Block a user