Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ php artisan admin:install
- 增强枚举(`BackedEnum`)字段的渲染支持
- 支持 `.5` 列宽,如 `col-sm-1.5`
- 优化 HTTPS 站点的资源 URL 生成
- **新增 URL 主键加密**:可对路由路径中的主键(如 `/admin/books/{id}/edit`)进行加密(默认 36 位 UUID 样式密文),防止直接暴露数据库主键;支持 `encrypt` / `cipher` / `cipher_salt` 配置与手动加解密 Helper,详见 [加密功能使用说明](docs/url-cipher-guide.md)

### Bug 修复

Expand All @@ -70,6 +71,18 @@ php artisan admin:install
- [English documentation](http://www.dcatadmin.com/docs/en-2.x/quick-start.html)
- [原项目 README(功能特性、扩展、鸣谢)](README.origin.md)

项目扩展能力专项说明:

- [URL 主键加密功能使用说明](docs/url-cipher-guide.md)

## 扩展包

| 扩展 | 描述 | dcat-admin 版本 |
| --- |----------------------------------------------|---------------|
| [zgy-dcat/wangeditor](https://github.com/gy23rm/dcat-wangeditor) | wangEditor 5 富文本编辑器表单字段 | dev-master |
| [zgy-dcat/distpicker](https://github.com/gy23rm/dcat-distpicker) | 省市区三级联动(super-eggs/dcat-distpicker 的维护 fork) |dev-master |
| [zgy-dcat/master-detail](https://github.com/gy23rm/dcat-master-detail) | 左树右表联动(Master-Detail)扩展 |dev-master |

## 免责声明

本项目已通过测试并在实际生产环境中使用,但无法保证所有修改绝对无误,上线前请充分测试。
Expand Down
12 changes: 4 additions & 8 deletions composer.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"name": "printnow/laravel-admin",
"name": "zgy-dcat/laravel-admin",
"description": "Dcat admin 永久分叉版 / 支持 Laravel 10-13, PHP 版本限制 >= 8.1(支持 PHP 8.5)",
"type": "library",
"keywords": [
Expand All @@ -11,16 +11,12 @@
"laravel admin",
"dcat admin"
],
"homepage": "https://github.com/PrintNow/dcat-admin",
"homepage": "https://github.com/gy23rm/dcat-admin",
"license": "MIT",
"authors": [
{
"name": "Shine",
"email": "[email protected]"
},
{
"name": "jqh",
"email": "[email protected]"
"name": "zgy",
"email": "[email protected]"
}
],
"require": {
Expand Down
36 changes: 36 additions & 0 deletions config/admin.php
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,42 @@
'middleware' => ['web', 'admin'],

'enable_session_middleware' => false,

/*
|--------------------------------------------------------------------------
| 主键加密
|--------------------------------------------------------------------------
|
| 开启后,Grid/Form 生成的路径参数中的记录主键会被加密
| (如 /users/{id}/edit 中的 {id}),请求进入时由 admin.cipher
| 中间件自动解密,控制器拿到的永远是明文主键。
|
| 仅加密主键;其它查询参数(过滤条件等)保持明文,不做处理。
|
| encrypt: 是否启用
| cipher : 加解密实现类,必须实现 \Dcat\Admin\Contracts\UrlCipher
| 当前默认 UuidCipher(AES 伪 UUID 版,密文为 36 位 UUID 格式;
| 仅支持正整数主键,范围 1 ~ 1099511627775(uint40);
| 作用域内嵌密文,从 cipher_salt 派生 AES 密钥)
| 可选 CryptCipher(配置盐混淆版;盐为空会报错)
| cipher_salt : 加解密盐(字符串),用于派生混淆字节流;必须有值,为空会抛异常
| cipher_magic : UuidCipher 明文块第一字节魔数(默认 "\x02")。可配 int / 0x 十六进制
| 字符串 / "\x01" 转义字符串,最终归一为单字节;加解密共用该值。
| 注意:改动它会让旧密文无法解密(解密魔数也会变),如无必要请保持默认。
| cipher_scopes : (历史兼容,可保留)作用域常量数组扩展,仅旧版 UuidCipher 强制校验
| 注册用。当前实现不再强制校验作用域范围;作用域必须是 1~2 个可打印
| ASCII 字符的短标签(如 gi / fo / bo),超长(如 book:grid.id)加密时报错。
| 以下配置仅为历史兼容保留,可删除
*/
'encrypt' => env('ADMIN_ROUTE_ENCRYPT', false),

'cipher' => \Dcat\Admin\Support\UuidCipher::class,

'cipher_salt' => env('ADMIN_ROUTE_CIPHER_SALT', 'dcat_c'),

'cipher_magic' => "\x02",

'cipher_scopes' => [],
],

/*
Expand Down
Loading
Loading