|
35778
|
5
|
5
|
5
|
124
|
0
|
0
|
refs/heads/claude/ac79-wall
|
1
|
|
1791561712
|
Edit
Delete
|
|
35779
|
5
|
5
|
5
|
124
|
0
|
0
|
refs/heads/claude/ac79-wall
|
1
|
{"Commits":[{"Sha1":"26f9342d4 {"Commits":[{"Sha1":"26f9342d4f41c91a5b6edd2fc740db99708e434f","Message":"feat(AC79): move video wall layout controls into the domain and add evidence\n\nAC79 (HQR04) was the only non-external acceptance case without named\nevidence: group/flat, 4/9/16, paging, sorting and rotation switches must\nkeep the scope, and mobile focus/return must stay reachable.\n\n- hq-wall-domain: wallControl() owns slots/sort/pin/mode/page/tour changes\n and never touches store, region, type or point scope; wallSections()\n derives group/flat sections for the current page.\n- HeadquartersConsole/VideoWall use them instead of inline setters; the\n behavior is unchanged (layout, risk-first, manual paging, focus and talk\n stop rotation; group/flat keeps the page; sort/pin/layout reset to page 1).\n- New AC79 test walks every switch over three scopes and checks each page\n covers the scope exactly once; AC79 maps to it.\n- Browser (store dev server, demo data): 北区 scope stayed 12 cameras/3\n stores through 4-\u003eflat-\u003erisk-\u003e16; next-page stopped rotation; at 375px,\n focus moved to the detail panel and return restored scroll and the\n original focus button.\n\nCo-Authored-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-10-09T09:01:50-07:00"}],"HeadCommit":{"Sha1":"26f9342d4f41c91a5b6edd2fc740db99708e434f","Message":"feat(AC79): move video wall layout controls into the domain and add evidence\n\nAC79 (HQR04) was the only non-external acceptance case without named\nevidence: group/flat, 4/9/16, paging, sorting and rotation switches must\nkeep the scope, and mobile focus/return must stay reachable.\n\n- hq-wall-domain: wallControl() owns slots/sort/pin/mode/page/tour changes\n and never touches store, region, type or point scope; wallSections()\n derives group/flat sections for the current page.\n- HeadquartersConsole/VideoWall use them instead of inline setters; the\n behavior is unchanged (layout, risk-first, manual paging, focus and talk\n stop rotation; group/flat keeps the page; sort/pin/layout reset to page 1).\n- New AC79 test walks every switch over three scopes and checks each page\n covers the scope exactly once; AC79 maps to it.\n- Browser (store dev server, demo data): 北区 scope stayed 12 cameras/3\n stores through 4-\u003eflat-\u003erisk-\u003e16; next-page stopped rotation; at 375px,\n focus moved to the detail panel and return restored scroll and the\n original focus button.\n\nCo-Authored-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-10-09T09:01:50-07:00"},"CompareURL":"luoanwu/haizan-self-service-ktv/compare/4188dc17cbab255ac72715a4b78a0640a4c6b541...26f9342d4f41c91a5b6edd2fc740db99708e434f","Len":1}...
|
1791561712
|
Edit
Delete
|
|
35780
|
5
|
7
|
5
|
124
|
0
|
0
|
|
1
|
15|docs: record verbal confirmation of development 15|docs: record verbal confirmation of development defaults (2026-10-09)...
|
1791561737
|
Edit
Delete
|
|
35781
|
5
|
11
|
5
|
124
|
0
|
0
|
|
1
|
15|docs: record verbal confirmation of development 15|docs: record verbal confirmation of development defaults (2026-10-09)...
|
1791561742
|
Edit
Delete
|
|
35782
|
5
|
5
|
5
|
124
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"63e64351d {"Commits":[{"Sha1":"63e64351d3526e31032e2ced6898cbebeceab89d","Message":"Merge pull request 'docs: record verbal confirmation of development defaults (2026-10-09)' (#15) from claude/approve-dev-defaults into main\n\nReviewed-on: https://gitea.g-hi.com/luoanwu/haizan-self-service-ktv/pulls/15\n","AuthorEmail":"law@g-hi.com","AuthorName":"luoanwu","CommitterEmail":"law@g-hi.com","CommitterName":"luoanwu","Timestamp":"2026-10-10T00:02:21+08:00"},{"Sha1":"dc79c45434ebe8fffe4d08a33b66e2350c4ead52","Message":"docs: regenerate acceptance matrix after the GOV01 renewal merges (903/903)\n\nMain's matrix was produced before #12/#13 changed sources, so --check reported\nit stale. This run on the merged sources restores check=0.\n\nCo-Authored-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-10-09T08:59:39-07:00"},{"Sha1":"cd7e6fe99e2464b637483dde49247e949d5fc95e","Message":"docs: record verbal confirmation of development defaults (2026-10-09)\n\nThe project owner confirmed every development default in the table, including\nthe late flash-sale payment and interrupted-transcript rules. This records a\nverbal confirmation only: code policies stay approved:false until a formal\napproval record exists, and no real provider is enabled by it.\n\nCo-Authored-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-10-09T08:59:09-07:00"}],"HeadCommit":{"Sha1":"63e64351d3526e31032e2ced6898cbebeceab89d","Message":"Merge pull request 'docs: record verbal confirmation of development defaults (2026-10-09)' (#15) from claude/approve-dev-defaults into main\n\nReviewed-on: https://gitea.g-hi.com/luoanwu/haizan-self-service-ktv/pulls/15\n","AuthorEmail":"law@g-hi.com","AuthorName":"luoanwu","CommitterEmail":"law@g-hi.com","CommitterName":"luoanwu","Timestamp":"2026-10-10T00:02:21+08:00"},"CompareURL":"luoanwu/haizan-self-service-ktv/compare/4188dc17cbab255ac72715a4b78a0640a4c6b541...63e64351d3526e31032e2ced6898cbebeceab89d","Len":3}...
|
1791561743
|
Edit
Delete
|
|
35802
|
5
|
7
|
5
|
124
|
0
|
0
|
|
1
|
16|docs: 开发默认值口头确认,并刷新验收矩阵
|
1791588968
|
Edit
Delete
|
|
35808
|
5
|
7
|
5
|
124
|
0
|
0
|
|
1
|
17|feat(AC79): move video wall layout controls int 17|feat(AC79): move video wall layout controls into the domain and add evidence...
|
1791589291
|
Edit
Delete
|
|
35809
|
5
|
11
|
5
|
124
|
0
|
0
|
|
1
|
17|feat(AC79): move video wall layout controls int 17|feat(AC79): move video wall layout controls into the domain and add evidence...
|
1791589300
|
Edit
Delete
|
|
35810
|
5
|
5
|
5
|
124
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"bd0cd1cff {"Commits":[{"Sha1":"bd0cd1cff48ffa2f052eef3e6094746a38657a3b","Message":"Merge pull request 'feat(AC79): move video wall layout controls into the domain and add evidence' (#17) from claude/ac79-wall into main\n\nReviewed-on: https://gitea.g-hi.com/luoanwu/haizan-self-service-ktv/pulls/17\n","AuthorEmail":"law@g-hi.com","AuthorName":"luoanwu","CommitterEmail":"law@g-hi.com","CommitterName":"luoanwu","Timestamp":"2026-10-10T07:41:39+08:00"},{"Sha1":"26f9342d4f41c91a5b6edd2fc740db99708e434f","Message":"feat(AC79): move video wall layout controls into the domain and add evidence\n\nAC79 (HQR04) was the only non-external acceptance case without named\nevidence: group/flat, 4/9/16, paging, sorting and rotation switches must\nkeep the scope, and mobile focus/return must stay reachable.\n\n- hq-wall-domain: wallControl() owns slots/sort/pin/mode/page/tour changes\n and never touches store, region, type or point scope; wallSections()\n derives group/flat sections for the current page.\n- HeadquartersConsole/VideoWall use them instead of inline setters; the\n behavior is unchanged (layout, risk-first, manual paging, focus and talk\n stop rotation; group/flat keeps the page; sort/pin/layout reset to page 1).\n- New AC79 test walks every switch over three scopes and checks each page\n covers the scope exactly once; AC79 maps to it.\n- Browser (store dev server, demo data): 北区 scope stayed 12 cameras/3\n stores through 4-\u003eflat-\u003erisk-\u003e16; next-page stopped rotation; at 375px,\n focus moved to the detail panel and return restored scroll and the\n original focus button.\n\nCo-Authored-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-10-09T09:01:50-07:00"}],"HeadCommit":{"Sha1":"bd0cd1cff48ffa2f052eef3e6094746a38657a3b","Message":"Merge pull request 'feat(AC79): move video wall layout controls into the domain and add evidence' (#17) from claude/ac79-wall into main\n\nReviewed-on: https://gitea.g-hi.com/luoanwu/haizan-self-service-ktv/pulls/17\n","AuthorEmail":"law@g-hi.com","AuthorName":"luoanwu","CommitterEmail":"law@g-hi.com","CommitterName":"luoanwu","Timestamp":"2026-10-10T07:41:39+08:00"},"CompareURL":"luoanwu/haizan-self-service-ktv/compare/63e64351d3526e31032e2ced6898cbebeceab89d...bd0cd1cff48ffa2f052eef3e6094746a38657a3b","Len":2}...
|
1791589301
|
Edit
Delete
|
|
35132
|
16
|
1
|
16
|
125
|
0
|
0
|
|
0
|
|
1791450264
|
Edit
Delete
|
|
35930
|
16
|
5
|
16
|
125
|
0
|
0
|
refs/heads/main
|
0
|
|
1791611083
|
Edit
Delete
|
|
35931
|
16
|
5
|
16
|
125
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"958ef4eaa {"Commits":[{"Sha1":"958ef4eaa9c5c873973a94474f7ffb6ab9c16cd2","Message":"fix(mfa): 限制初始管理员凭据并原子完成首次开通\n\n初始管理员密码原先没有有效期,首次绑定后仍可作为长期密码使用。增加固定开通期限并要求绑定时设置正式密码,保留现有 MFA 安全机制。\n\n实现内容:\n- V24 增加初始凭据截止和完成标记,固定 24 小时有效,受限会话仍最多 300 秒且不能越过开户期限\n- 正式密码替换、TOTP 消费、因素绑定、恢复码生成及审计原子提交,撤销旧身份并创建新会话\n- 处理并发开通的浏览器会话清理,仅续办当前浏览器的有效 OIDC 交易且不延长交易期限\n- 增加离线重新签发命令和私密交付流程,禁止用于已绑定账号;前端仍要求确认保存恢复码\n- 补充开通、迁移、并发、事务回滚、前端和交付脚本测试,同步账号与 MFA 合同\n\n验证:\n- Maven 定向 verify:BootstrapEnrollmentIT 10 项、AccountsIT 15 项、MfaIT 34 项、TotpTest 3 项通过\n- AttackProtectionIT 12 项、SessionLifecycleIT 26 项、AuthorizationIT 26 项、BrowserSecurityIT 5 项通过\n- 初始凭据及三类 MFA 迁移测试各 1 项通过;AuthorizationMigrationIT 修正旧版本断言后 3 项通过\n- npm run check:21 个文件 173 项测试以及格式、lint、类型检查、构建通过\n- python3 deploy/lab/test-bootstrap.py:3 项通过\n- Maven console profile package 通过,最终 JAR 的前端资源和 V24 迁移与工作区一致\n- 后端全量测试及本阶段真实浏览器验收未运行\n\nBREAKING CHANGE: 需执行 V24 并同步升级前后端;历史未绑定初始管理员必须离线重新签发,初始开通确认接口新增必填 new_password,旧实例不能混跑\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-09T18:38:18+08:00"},{"Sha1":"f59b781e837c7cc0afc4916f4e7ace4d5e37f760","Message":"fix(mfa): 修复受限会话恢复并增加递增冷却\n\n修复受限 MFA 会话过期后的页面恢复,并区分挑战终态与临时限流,防止用户等待后继续提交已失效的挑战。\n\n实现内容:\n- 全局 401 覆盖 PENDING/RECOVERY,补充 MFA 路由保护和明确退出导航\n- 挑战及绑定截止不晚于基础会话期限,终态要求重新开始,临时限流按 Retry-After 等待且不自动提交\n- V23 增加账号共享失败累计,每五次无效证明按 30/60/120/300 秒递增冷却,并原子记录审计与 Outbox\n- 保留 TOTP 防重放、恢复码单次消费、管理员禁止停用及独立二次验证授权\n- 补充集成、迁移、前端与浏览器验收测试,同步接口合同\n\n验证:\n- Maven 定向 verify:TotpTest 3 项、AttackProtectionIT 12 项、BrowserSecurityIT 5 项及三类 MFA 迁移测试各 1 项通过\n- MfaIT 首轮两项测试夹具异常已修复,定向 verify 重跑 34 项全部通过\n- npm run check:21 个文件共 171 项测试通过,格式、lint、类型及构建通过;最终脚本补测后格式与 lint 再次通过\n- Maven console profile package 成功,最终 JAR 浏览器 S01—S07 完整通过,S08 正式登录路由单独补测通过\n- 后端全量测试及原 P11 浏览器全套未运行\n\nBREAKING CHANGE: 挑战耗尽由 429 改为 400,新增 MFA_CHALLENGE_CONSUMED 和 MFA_COOLDOWN;需执行 V23、同步升级前后端并协调停止旧实例\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-09T18:13:57+08:00"},{"Sha1":"c0aca8ed9cb6c24340ab9a6cf3c22ff42d68c59b","Message":"fix(mfa): 为敏感因素操作增加独立二次验证授权\n\n登录验证不再授权认证器重绑、恢复码再生成或停用 MFA,敏感操作必须完成新的 TOTP 验证。\n\n实现内容:\n- 新增 V22 授权表,绑定用户、会话、因素代际与操作类型,五分钟有效并在业务事务内原子消费\n- 保持首次绑定与恢复码受限重绑、管理员禁用限制及普通管理会话强度语义\n- 前端按具体操作弹出验证,身份变化、取消或过期终止,成功后最多续办一次并使用轮换后的 CSRF\n- 补充迁移、授权边界、前端续办测试以及接口文档和浏览器验收脚本\n\n验证:\n- MfaIT 23、AttackProtectionIT 12、TotpTest 3、BrowserSecurityIT 5、MfaMigrationIT 1、MfaStepUpMigrationIT 1 均通过\n- npm run check 通过:20 个文件共 157 项测试,格式、静态检查、类型检查与构建通过\n- 最后调整验收脚本后 npm run format:check 通过;console 制品打包通过\n- 最终制品的真实浏览器 12 个场景分两轮覆盖通过;完整单轮受账号限流影响,脚本已加入窗口等待\n- git diff --check 通过;后端全量测试未运行\n\nBREAKING CHANGE: 敏感因素操作需在挑战中指定 operation 并携带 X-MFA-Step-Up 授权。上线须执行 V22 并同步升级前后端,旧实例不可混跑;升级会清除未完成的绑定候选。\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-09T17:17:07+08:00"},{"Sha1":"7f8cdc4698e73b2af30f932250521b0d12198f06","Message":"chore(evidence): 外置验收截图并记录历史清理映射\n\n批量浏览器截图占据仓库主要体积,改为独立归档并保留证据追溯方式。\n\n实现内容:\n- 排除 docs/evidence 下批量图片再次进入版本控制,保留其他文档图片\n- 增加 3473 张截图的归档校验清单及 146 个历史提交的新旧映射\n- 将 534 处截图链接指向归档说明并保留原路径,补充恢复及后续证据规则\n\n验证:\n- 146 个历史提交的非截图文件及父提交关系逐一核对通过\n- 3473 张归档图片逐一核对 SHA-256,通过归档完整性检查\n- 全部归档图片被忽略,其他文档图片未被误排除\n- 534 处改写链接目标校验及 git diff --check 通过\n- 未运行业务测试,本次没有修改业务代码或测试断言\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-09T15:37:26+08:00"},{"Sha1":"7da2727c1fa0b56e93f3c0bf68882dedc18dc46d","Message":"docs(capacity): 归档生命周期锁优化与两小时故障复验\n\n记录共享生命周期读锁候选的同条件短测、正式稳定性及故障复验,保留失败与修正,并按原预算维持未通过裁决。\n\n实现内容:\n- 归档原始样本、源码摘要、曲线、认证方案评审及复算脚本\n- 同步开发计划和容量任务,区分历史、诊断、正式结果及目标缺口\n- 固定派生CSV使用LF,核对220份证据摘要与Git暂存内容一致\n- 保留耗尽探针首次失败及补测,记录7个独立环境与私有材料清理\n\n验证:\n- 冻结候选 ./mvnw -B -ntp clean verify -Pconsole:491个唯一测试通过,零失败、零跳过,AOSP及冻结前端构建通过\n- Python统计合同11项通过;最终故障工具javac及AOSP通过\n- 正式7200秒:815729成功、31错误、零漏发和429;刷新P95 303.72ms仍超过200ms预算\n- 10类低档隔离探针及9类持续背景故障最终通过,初次失败与预热错误保留\n- 归档JSON/Python语法、摘要与git diff --cached --check通过\n- L1自身目标仍未满足,限定试运行依据不足,P12未通过;未进入P13、未推送\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-08T20:21:54+08:00"}],"HeadCommit":{"Sha1":"958ef4eaa9c5c873973a94474f7ffb6ab9c16cd2","Message":"fix(mfa): 限制初始管理员凭据并原子完成首次开通\n\n初始管理员密码原先没有有效期,首次绑定后仍可作为长期密码使用。增加固定开通期限并要求绑定时设置正式密码,保留现有 MFA 安全机制。\n\n实现内容:\n- V24 增加初始凭据截止和完成标记,固定 24 小时有效,受限会话仍最多 300 秒且不能越过开户期限\n- 正式密码替换、TOTP 消费、因素绑定、恢复码生成及审计原子提交,撤销旧身份并创建新会话\n- 处理并发开通的浏览器会话清理,仅续办当前浏览器的有效 OIDC 交易且不延长交易期限\n- 增加离线重新签发命令和私密交付流程,禁止用于已绑定账号;前端仍要求确认保存恢复码\n- 补充开通、迁移、并发、事务回滚、前端和交付脚本测试,同步账号与 MFA 合同\n\n验证:\n- Maven 定向 verify:BootstrapEnrollmentIT 10 项、AccountsIT 15 项、MfaIT 34 项、TotpTest 3 项通过\n- AttackProtectionIT 12 项、SessionLifecycleIT 26 项、AuthorizationIT 26 项、BrowserSecurityIT 5 项通过\n- 初始凭据及三类 MFA 迁移测试各 1 项通过;AuthorizationMigrationIT 修正旧版本断言后 3 项通过\n- npm run check:21 个文件 173 项测试以及格式、lint、类型检查、构建通过\n- python3 deploy/lab/test-bootstrap.py:3 项通过\n- Maven console profile package 通过,最终 JAR 的前端资源和 V24 迁移与工作区一致\n- 后端全量测试及本阶段真实浏览器验收未运行\n\nBREAKING CHANGE: 需执行 V24 并同步升级前后端;历史未绑定初始管理员必须离线重新签发,初始开通确认接口新增必填 new_password,旧实例不能混跑\n","AuthorEmail":"gamebyteyu@gmail.com","AuthorName":"starry","CommitterEmail":"gamebyteyu@gmail.com","CommitterName":"starry","Timestamp":"2026-10-09T18:38:18+08:00"},"CompareURL":"pengzhiyu/IAM/compare/bff0faf3451547b455191b02c7cf7ca2a1c1ee80...958ef4eaa9c5c873973a94474f7ffb6ab9c16cd2","Len":10}...
|
1791611083
|
Edit
Delete
|
|
36291
|
16
|
5
|
16
|
125
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"06556f73e {"Commits":[{"Sha1":"06556f73ea74b431979b8b819de8e85358843b49","Message":"perf: 优化客户端凭据校验与授权查询并补充容量观测\n\nP12 L1 尚未通过,先实现客户端校验、授权查询与观测工具的第一批调整,供另一台 JDK 25 设备编译回归后形成云端测试候选;本提交不代表性能验收通过。\n\n实现内容:\n- 新客户端秘密采用用途独立的版本化 HMAC-SHA256,兼容历史 BCrypt12;通过 V25 显式激活密钥权威并守卫凭据写入\n- 增加普通客户端秘密轮换及认证换代复核,补充协议、密钥策略、部署辅助工具与测试源码\n- 通过 V26 缩小目标企业资格查询,批量计算组织范围,将本地缓存调整为有界 LRU\n- 增加认证、锁、缓存及连接池指标,补充 legacy/hmac/mixed 容量模式、Linux 临时路径与候选摘要核对\n- 更新部署说明和 P12 交接,明确另一设备先完成构建回归,随后再进行云端隔离性能测试\n\n验证:\n- google-java-format 1.35.0 --aosp --dry-run --set-exit-if-changed:51 个新增或修改 Java 文件通过\n- Python AST 解析:11 个新增或修改 Python 文件通过,仅语法检查,未导入或执行脚本\n- git diff --check:通过;新增文档相对文件链接检查通过\n- 当前默认 Java 21,按用户安排未运行 Maven/Spotless 全工程门禁、编译、测试、数据库迁移、容器或压测;须在 JDK 25 设备继续验收\n\nBREAKING CHANGE: 启动前必须准备 IAM_CLIENT_SECRET_KEY_RING_FILE 并以迁移身份显式激活权威集合;写入 HMAC 凭据后不支持直接回退旧二进制\n","AuthorEmail":"228834386@qq.com","AuthorName":"starry","CommitterEmail":"228834386@qq.com","CommitterName":"starry","Timestamp":"2026-10-10T17:56:32+08:00"}],"HeadCommit":{"Sha1":"06556f73ea74b431979b8b819de8e85358843b49","Message":"perf: 优化客户端凭据校验与授权查询并补充容量观测\n\nP12 L1 尚未通过,先实现客户端校验、授权查询与观测工具的第一批调整,供另一台 JDK 25 设备编译回归后形成云端测试候选;本提交不代表性能验收通过。\n\n实现内容:\n- 新客户端秘密采用用途独立的版本化 HMAC-SHA256,兼容历史 BCrypt12;通过 V25 显式激活密钥权威并守卫凭据写入\n- 增加普通客户端秘密轮换及认证换代复核,补充协议、密钥策略、部署辅助工具与测试源码\n- 通过 V26 缩小目标企业资格查询,批量计算组织范围,将本地缓存调整为有界 LRU\n- 增加认证、锁、缓存及连接池指标,补充 legacy/hmac/mixed 容量模式、Linux 临时路径与候选摘要核对\n- 更新部署说明和 P12 交接,明确另一设备先完成构建回归,随后再进行云端隔离性能测试\n\n验证:\n- google-java-format 1.35.0 --aosp --dry-run --set-exit-if-changed:51 个新增或修改 Java 文件通过\n- Python AST 解析:11 个新增或修改 Python 文件通过,仅语法检查,未导入或执行脚本\n- git diff --check:通过;新增文档相对文件链接检查通过\n- 当前默认 Java 21,按用户安排未运行 Maven/Spotless 全工程门禁、编译、测试、数据库迁移、容器或压测;须在 JDK 25 设备继续验收\n\nBREAKING CHANGE: 启动前必须准备 IAM_CLIENT_SECRET_KEY_RING_FILE 并以迁移身份显式激活权威集合;写入 HMAC 凭据后不支持直接回退旧二进制\n","AuthorEmail":"228834386@qq.com","AuthorName":"starry","CommitterEmail":"228834386@qq.com","CommitterName":"starry","Timestamp":"2026-10-10T17:56:32+08:00"},"CompareURL":"pengzhiyu/IAM/compare/958ef4eaa9c5c873973a94474f7ffb6ab9c16cd2...06556f73ea74b431979b8b819de8e85358843b49","Len":1}...
|
1791626275
|
Edit
Delete
|