fix: tts fileID 校验归属 + 排行榜不下发他人 openid

- tts: client 传的 fileID 校验必须属于 tts-cache 目录,防伪造 cloud:// 换取他人私有文件
- leaderboard: ranked 去掉他人 openid 改用 isMe 标记,wxml 用 item.isMe 高亮

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
liucheng
2026-07-25 14:59:15 +08:00
parent 88a2c349f4
commit 41aa81083f
3 changed files with 4 additions and 2 deletions
+1 -1
View File
@@ -155,7 +155,7 @@ exports.main = async (event) => {
// Top N for the board
const ranked = allSorted.slice(0, limit).map((item, i) => ({
rank: i + 1,
openid: item.openid,
isMe: item.openid === myOpenid,
nickname: item.nickname || '',
name: _displayName(item),
duration: item.duration,
+2
View File
@@ -85,6 +85,8 @@ exports.main = async (event) => {
// 解析 fileID:优先 client 传入,否则查服务端 tts_cache,防 client 传 null 强制重合成(刷 TTS 账单)
let resolvedFileID = fileID || null
// 校验 client 传的 fileID 必须属于 tts-cache 目录,防伪造 cloud:// 换取他人私有文件
if (resolvedFileID && !resolvedFileID.includes(CACHE_DIR)) resolvedFileID = null
if (!resolvedFileID) {
try {
const r = await db.collection('tts_cache').doc(cacheKey).get()