diff --git a/backend/api/server.py b/backend/api/server.py index 48b95ef..d83520b 100644 --- a/backend/api/server.py +++ b/backend/api/server.py @@ -4556,28 +4556,6 @@ def _safe_account_id(account_id: str | None) -> str: return normalized[:80] or 'default' -_XIAOMI_EMAIL_RE = re.compile(r'^([\w.-]+)@xiaomi\.com$', re.IGNORECASE) -_EMAIL_ACCOUNT_ID_RE = re.compile(r'^[a-z0-9._-]{2,40}$') - - -def _account_id_from_email(email: str | None) -> str | None: - """Validate a Xiaomi email and return its prefix as account_id. - - The prefix is lowercased and must satisfy the platform account_id rule: - only lowercase letters / digits / dot / underscore / dash, length 2-40. - Returns None if the email or prefix is invalid (caller must reject). - """ - if not isinstance(email, str): - return None - match = _XIAOMI_EMAIL_RE.match(email.strip()) - if not match: - return None - prefix = match.group(1).lower() - if not _EMAIL_ACCOUNT_ID_RE.match(prefix): - return None - return prefix - - def _linux_accounts_enabled() -> bool: return os.environ.get(LINUX_ACCOUNT_ENV, '').strip().lower() in { '1', diff --git a/frontend/app/lib/claw-auth.ts b/frontend/app/lib/claw-auth.ts index ee5c356..2ba811f 100644 --- a/frontend/app/lib/claw-auth.ts +++ b/frontend/app/lib/claw-auth.ts @@ -103,6 +103,7 @@ export async function registerByEmail(email: string, password: string) { createdAt: new Date().toISOString(), }; usersFile.users.push(account); + await ensureLinuxAccount(account.id, password); await writeUsers(usersFile); await createAccountDirectories(account.id); return createSession(account); @@ -121,6 +122,7 @@ export async function loginByEmail(email: string, password: string) { if (!verifyPassword(password, account.passwordHash)) { throw new Error("邮箱或密码错误"); } + await ensureLinuxAccount(account.id, password); await createAccountDirectories(account.id); return createSession(account); }