feat(security): implement dynamic tactical license gate, instant key revocation, and clean hardcoded credentials
This commit is contained in:
@@ -328,9 +328,14 @@ const app = {
|
||||
</div>
|
||||
</td>
|
||||
<td class="px-6 py-6 text-right">
|
||||
<button class="p-2 text-slate-500 hover:text-white" onclick="app.fetchData()">
|
||||
<i data-lucide="refresh-cw" class="w-4 h-4"></i>
|
||||
</button>
|
||||
<div class="flex items-center justify-end gap-1">
|
||||
<button class="p-2 text-slate-500 hover:text-white" title="Refresh" onclick="app.fetchData()">
|
||||
<i data-lucide="refresh-cw" class="w-4 h-4"></i>
|
||||
</button>
|
||||
<button class="p-2 text-slate-500 hover:text-red-400 transition-colors" title="Revoke Key" onclick="app.deleteKey('${key.id}', '${key.name}')">
|
||||
<i data-lucide="trash-2" class="w-4 h-4"></i>
|
||||
</button>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
`;
|
||||
@@ -339,6 +344,29 @@ const app = {
|
||||
lucide.createIcons();
|
||||
},
|
||||
|
||||
deleteKey: async (keyId, keyName) => {
|
||||
if (!confirm(`Are you sure you want to revoke the API key "${keyName || 'Production Key'}"? This action cannot be undone.`)) {
|
||||
return;
|
||||
}
|
||||
|
||||
try {
|
||||
const res = await fetch(`/api/auth/management/keys/${keyId}`, {
|
||||
method: 'DELETE',
|
||||
headers: auth.getAuthHeader()
|
||||
});
|
||||
|
||||
if (res.ok) {
|
||||
await app.fetchData();
|
||||
} else {
|
||||
const data = await res.json().catch(() => ({}));
|
||||
alert(data.message || 'Failed to revoke API key');
|
||||
}
|
||||
} catch (e) {
|
||||
console.error('Delete key failed:', e);
|
||||
alert('Failed to revoke API key');
|
||||
}
|
||||
},
|
||||
|
||||
toggleKeyVisibility: (id) => {
|
||||
app.state.showKeys[id] = !app.state.showKeys[id];
|
||||
app.renderKeysTable();
|
||||
|
||||
Reference in New Issue
Block a user