feat(admin): M2 WebUI 管理后台(鉴权+仪表盘+音色 CRUD)

新增 /admin 管理后台,Vue3 + axios 单文件 SPA。

新增:
- middleware/admin_auth.go: RequireAdmin 中间件
  复用 OPENAI_TTS_API_KEY(Bearer),密钥为空等同无鉴权;
  常量时间比较防计时攻击(用 common.SecureEqualString);
  401 + WWW-Authenticate 头 + JSON 错误体。
- controller/admin.go: 5 个 admin handler
  - GET /api/admin/overview: 模式/db路径/lock/版本/运行时间/音色数/内存
  - GET /api/admin/metrics: 鉴权版 Prometheus 文本(无鉴权版 /metrics 仍给 Prometheus)
  - GET /api/voices: 列表(含 disabled)
  - POST /api/voices: 新增,409 处理重复,400 处理字段不合法
  - DELETE /api/voices/{name}: 删除,409 处理被 default_speaker 引用
  - PATCH /api/voices/{name}/toggle: 启停
- router/admin.html: 单文件 SPA(18KB)
  登录页(单 input) + 仪表盘(metrics cards) + 音色 tab(表格+新增+启停+删除);
  hash 路由切 tab;axios 拦截器自动加 Bearer,401 回登录页;
  sessionStorage 存 key(关浏览器失效)。
- common/constants.go: SecureEqualString 提取到公共包
  controller/setup.go + middleware/admin_auth.go 共用,避免重复实现。

改造:
- router/router.go: 挂 /admin(/admin HTML 公开,鉴权由前端 JS 拦截)
  + /api/admin/{overview,metrics} + /api/voices{,/{name},/{name}/toggle}
  全部 API 端点套 RequireAdmin;正常模式 / → 302 /admin(M2 优先于 /dashboard)。
- main.go: 启动期调 SetAdminStore + SetMetricsTextWriter(避免 controller → metrics cycle)
- metrics/metrics.go: AdapterRecorder 用 SpeakerLabel 替代明文 speaker
  (这是第 4 处 speaker 泄漏,顺带补上;前面 3 处在 51bd7ae 已修)。
- controller/setup.go: 用 common.SecureEqualString 替自己的实现(去重)。

测试(都被 .gitignore 排除,本地保留):
- router/router_test.go: 更新 4 个 NotFound 测试路径(/admin 现是注册路由,不再 404)
- telemetry/labels_test.go: 已有 SpeakerLabel/MaskSpeaker 测试(M2 复用)

e2e 验证(本机跑通):
- /admin 200 HTML(无鉴权,前端 JS 拦截)
- /api/admin/overview 无 Bearer 401
- /api/admin/overview 错 Bearer 401
- /api/admin/overview 对 Bearer 200 + JSON
- /api/voices GET 200 + 2 voices
- /api/voices POST 201 + new voice
- /api/voices/{name} DELETE 200
- /api/voices/{name}/toggle PATCH 200 + updated voice
- 正常模式 / 302 /admin
- 启动日志 BYTEDANCE_TTS_SPEAKER 仍打码 S_G8****naJ1(前次 fix 生效)

二进制大小: 16MB → ~17MB(admin.html +5 个 handler + 中间件)

未 push(用户要求与 speaker fix 51bd7ae 一起发,等服务器测完 M1 后一起验证)
This commit is contained in:
sun
2026-08-29 21:53:19 +08:00
parent 51bd7ae37a
commit 70865a3cf4
8 changed files with 806 additions and 33 deletions
+40 -17
View File
@@ -18,10 +18,16 @@ var dashboardHTML []byte
//go:embed setup.html
var setupHTML []byte
//go:embed admin.html
var adminHTML []byte
// Setup 返回主路由。
// 中间件顺序(由外向内):
// SecurityHeaders → InstallGuard → RateLimit → ConcurrencyLimit → Logger → handler
// 关键: InstallGuard 必须在 RateLimit 之前,避免安装模式被限流计数污染。
//
// /admin 和 /api/admin/* 都加 RequireAdmin;InstallGuard 不预先放行(让安装模式下
// 自动 302 跳 /setup,体验一致)。
func Setup() *mux.Router {
r := mux.NewRouter()
@@ -31,23 +37,21 @@ func Setup() *mux.Router {
r.Use(middleware.ConcurrencyLimitWithMetrics)
r.Use(middleware.Logger)
// mux 的 NotFoundHandler 不会走 r.Use() 中间件链,
// 所以 InstallGuard 的内容协商在 404 路径上不生效。
// 手动设一个:安装模式 + 浏览器访问任意未注册路径 → 302 跳 /setup。
r.NotFoundHandler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
if installer.GetMode() == installer.ModeSetup && acceptsHTML(r.Header.Get("Accept")) {
http.Redirect(w, r, "/setup", http.StatusFound)
// mux 路由未匹配时 NotFoundHandler 单独处理(不走 r.Use() 中间件链);
// 安装模式 + 浏览器访问任意未注册路径 → 302 跳 /setup。
r.NotFoundHandler = http.HandlerFunc(func(w http.ResponseWriter, req *http.Request) {
if installer.GetMode() == installer.ModeSetup && acceptsHTML(req.Header.Get("Accept")) {
http.Redirect(w, req, "/setup", http.StatusFound)
return
}
http.NotFound(w, r)
http.NotFound(w, req)
})
// 安装相关路由(InstallGuard 已在 setup 模式放行;完成后由 controller 二次校验 404)
// /setup 页面本身:装完后必须不可用,否则用户敲 /setup 还会看到安装表单,容易误以为要重装。
// 装后跳 /admin(M2 之后才有;目前会 404,这是预期,比继续显示表单好)。
r.HandleFunc("/setup", func(w http.ResponseWriter, r *http.Request) {
r.HandleFunc("/setup", func(w http.ResponseWriter, req *http.Request) {
if installer.GetMode() == installer.ModeNormal {
http.Redirect(w, r, "/admin", http.StatusFound)
http.Redirect(w, req, "/admin", http.StatusFound)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
@@ -57,20 +61,40 @@ func Setup() *mux.Router {
r.HandleFunc("/api/setup/prefill", controller.SetupPrefillHandler).Methods("GET")
r.HandleFunc("/api/setup", controller.SetupSubmitHandler).Methods("POST")
// /admin 管理后台(M2);HTML 本身公开,鉴权由前端 JS 拦截
// (sessionStorage 没 key 就显示登录页;有 key 调 /api/admin/overview 触发 401 跳登录)
// API 端点(/api/admin/* /api/voices*)才需要 RequireAdmin。
r.HandleFunc("/admin", func(w http.ResponseWriter, req *http.Request) {
w.Header().Set("Content-Type", "text/html; charset=utf-8")
_, _ = w.Write(adminHTML)
}).Methods("GET")
// /api/admin/overview (鉴权)
r.Handle("/api/admin/overview", middleware.RequireAdmin(http.HandlerFunc(controller.AdminOverviewHandler))).Methods("GET")
// /api/admin/metrics (鉴权);返 Prometheus 文本
r.Handle("/api/admin/metrics", middleware.RequireAdmin(http.HandlerFunc(controller.AdminMetricsHandler))).Methods("GET")
// /api/voices 音色 CRUD (鉴权)
r.Handle("/api/voices", middleware.RequireAdmin(http.HandlerFunc(controller.AdminVoicesListHandler))).Methods("GET")
r.Handle("/api/voices", middleware.RequireAdmin(http.HandlerFunc(controller.AdminVoiceCreateHandler))).Methods("POST")
r.Handle("/api/voices/{name}", middleware.RequireAdmin(http.HandlerFunc(controller.AdminVoiceDeleteHandler))).Methods("DELETE")
r.Handle("/api/voices/{name}/toggle", middleware.RequireAdmin(http.HandlerFunc(controller.AdminVoiceToggleHandler))).Methods("PATCH")
// 业务路由
r.HandleFunc("/v1/audio/speech", controller.OpenaiTTSHandler).Methods("POST", "OPTIONS")
r.HandleFunc("/health", controller.HealthHandler).Methods("GET")
r.HandleFunc("/dashboard", func(w http.ResponseWriter, r *http.Request) {
r.HandleFunc("/dashboard", func(w http.ResponseWriter, req *http.Request) {
w.Header().Set("Content-Type", "text/html; charset=utf-8")
_, _ = w.Write(dashboardHTML)
}).Methods("GET")
r.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) {
// 安装模式下,根路径跳 /setup(给运维一个明显入口)
r.HandleFunc("/", func(w http.ResponseWriter, req *http.Request) {
// 安装模式下,根路径跳 /setup
if installer.GetMode() == installer.ModeSetup {
http.Redirect(w, r, "/setup", http.StatusFound)
http.Redirect(w, req, "/setup", http.StatusFound)
return
}
http.Redirect(w, r, "/dashboard", http.StatusFound)
// 正常模式:跳 /admin(M2 之后优先于 /dashboard)
http.Redirect(w, req, "/admin", http.StatusFound)
}).Methods("GET")
// /metrics 不做鉴权(对齐 /health 策略),但仍然走 RateLimit / ConcurrencyLimit。
@@ -80,9 +104,8 @@ func Setup() *mux.Router {
return r
}
// acceptsHTML 在 router 包内复刻一份,middleware 包的版本未导出。
// acceptsHTML 在 router 包内复刻,middleware 包的版本未导出。
// 用途:NotFoundHandler 判断浏览器 Accept。
// 与 middleware.acceptsHTML 行为一致(简单实现,严格匹配 text/html 或 text/*)。
func acceptsHTML(accept string) bool {
if accept == "" {
return false