|
| 1 | +import { NButton, NModal, NModalProvider, NSpin, NTag } from 'naive-ui' |
| 2 | +import { defineComponent, ref, watchEffect } from 'vue' |
| 3 | +import { marked } from 'marked' |
| 4 | +import { getReleaseDetails } from '../../external/api/github-check-update' |
| 5 | +import './markdown-styles.css' |
| 6 | + |
| 7 | +interface ReleaseDetails { |
| 8 | + name: string |
| 9 | + body: string |
| 10 | + html_url: string |
| 11 | + published_at: string |
| 12 | + tag_name: string |
| 13 | +} |
| 14 | + |
| 15 | +export const UpdateDetailModal = defineComponent({ |
| 16 | + props: { |
| 17 | + show: Boolean, |
| 18 | + version: String, |
| 19 | + repo: { |
| 20 | + type: String as () => 'mx-server' | 'mx-admin', |
| 21 | + required: true, |
| 22 | + }, |
| 23 | + title: String, |
| 24 | + }, |
| 25 | + emits: ['update:show'], |
| 26 | + setup(props, { emit }) { |
| 27 | + const loading = ref(false) |
| 28 | + const releaseDetails = ref<ReleaseDetails | null>(null) |
| 29 | + |
| 30 | + const fetchReleaseDetails = async () => { |
| 31 | + if (!props.version) return |
| 32 | + |
| 33 | + loading.value = true |
| 34 | + try { |
| 35 | + const details = await getReleaseDetails(props.repo, props.version) |
| 36 | + releaseDetails.value = details |
| 37 | + } catch (error) { |
| 38 | + console.error('获取发布详情失败:', error) |
| 39 | + } finally { |
| 40 | + loading.value = false |
| 41 | + } |
| 42 | + } |
| 43 | + |
| 44 | + watchEffect(() => { |
| 45 | + if (props.show && props.version) { |
| 46 | + fetchReleaseDetails() |
| 47 | + } |
| 48 | + }) |
| 49 | + |
| 50 | + const handleClose = () => { |
| 51 | + emit('update:show', false) |
| 52 | + } |
| 53 | + |
| 54 | + const openGitHub = () => { |
| 55 | + if (releaseDetails.value?.html_url) { |
| 56 | + window.open(releaseDetails.value.html_url, '_blank') |
| 57 | + } |
| 58 | + } |
| 59 | + |
| 60 | + const formatDate = (dateString: string) => { |
| 61 | + return new Date(dateString).toLocaleString('zh-CN') |
| 62 | + } |
| 63 | + |
| 64 | + // 简单的 HTML 清理函数,移除潜在的危险标签和属性 |
| 65 | + const sanitizeHtml = (html: string): string => { |
| 66 | + // 允许的标签和属性 |
| 67 | + const allowedTags = ['h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'p', 'br', 'strong', 'b', 'em', 'i', 'u', 'code', 'pre', 'blockquote', 'ul', 'ol', 'li', 'a', 'hr', 'table', 'thead', 'tbody', 'tr', 'th', 'td'] |
| 68 | + const allowedAttributes = ['href', 'title', 'target', 'rel'] |
| 69 | + |
| 70 | + // 移除 script 标签和 javascript: 协议 |
| 71 | + return html |
| 72 | + .replace(/<script\b[^<]*(?:(?!<\/script>)<[^<]*)*<\/script>/gi, '') |
| 73 | + .replace(/javascript:/gi, '') |
| 74 | + .replace(/on\w+\s*=/gi, '') // 移除事件处理器 |
| 75 | + } |
| 76 | + |
| 77 | + const formatMarkdown = (markdown: string): string => { |
| 78 | + if (!markdown) return '' |
| 79 | + |
| 80 | + try { |
| 81 | + // 使用 marked 库进行专业的 markdown 渲染 |
| 82 | + const result = marked.parse(markdown, { |
| 83 | + breaks: true, // 支持换行符转换为 <br> |
| 84 | + gfm: true, // 支持 GitHub Flavored Markdown |
| 85 | + }) |
| 86 | + |
| 87 | + // 确保返回字符串并进行安全清理 |
| 88 | + const htmlString = typeof result === 'string' ? result : markdown.replace(/\n/g, '<br>') |
| 89 | + return sanitizeHtml(htmlString) |
| 90 | + } catch (error) { |
| 91 | + console.error('Markdown 渲染失败:', error) |
| 92 | + // 降级到简单的文本显示 |
| 93 | + return markdown.replace(/\n/g, '<br>') |
| 94 | + } |
| 95 | + } |
| 96 | + |
| 97 | + return () => ( |
| 98 | + <NModal |
| 99 | + show={props.show} |
| 100 | + onUpdateShow={handleClose} |
| 101 | + preset="card" |
| 102 | + style={{ width: '600px', maxWidth: '90vw' }} |
| 103 | + title={props.title || '更新详情'} |
| 104 | + bordered={false} |
| 105 | + closable |
| 106 | + > |
| 107 | + <NSpin show={loading.value}> |
| 108 | + {releaseDetails.value ? ( |
| 109 | + <div class="space-y-4"> |
| 110 | + <div class="flex items-center justify-between"> |
| 111 | + <div> |
| 112 | + <h3 class="text-lg font-semibold mb-2"> |
| 113 | + {releaseDetails.value.name || releaseDetails.value.tag_name} |
| 114 | + </h3> |
| 115 | + <div class="flex items-center gap-2"> |
| 116 | + <NTag type="info">{releaseDetails.value.tag_name}</NTag> |
| 117 | + <span class="text-sm text-gray-500"> |
| 118 | + 发布于 {formatDate(releaseDetails.value.published_at)} |
| 119 | + </span> |
| 120 | + </div> |
| 121 | + </div> |
| 122 | + <NButton type="primary" onClick={openGitHub}> |
| 123 | + 在 GitHub 查看 |
| 124 | + </NButton> |
| 125 | + </div> |
| 126 | + |
| 127 | + {releaseDetails.value.body && ( |
| 128 | + <div class="mt-4"> |
| 129 | + <h4 class="font-medium mb-2">更新内容:</h4> |
| 130 | + <div |
| 131 | + class="prose prose-sm max-w-none p-4 bg-gray-50 rounded-lg dark:bg-gray-800 markdown-content leading-relaxed" |
| 132 | + innerHTML={formatMarkdown(releaseDetails.value.body)} |
| 133 | + /> |
| 134 | + </div> |
| 135 | + )} |
| 136 | + </div> |
| 137 | + ) : !loading.value ? ( |
| 138 | + <div class="text-center py-8 text-gray-500"> |
| 139 | + 无法获取更新详情 |
| 140 | + </div> |
| 141 | + ) : null} |
| 142 | + </NSpin> |
| 143 | + </NModal> |
| 144 | + ) |
| 145 | + }, |
| 146 | +}) |
| 147 | + |
| 148 | +export const useUpdateDetailModal = () => { |
| 149 | + const showModal = ref(false) |
| 150 | + const version = ref('') |
| 151 | + const repo = ref<'mx-server' | 'mx-admin'>('mx-server') |
| 152 | + const title = ref('') |
| 153 | + |
| 154 | + const openModal = (params: { |
| 155 | + version: string |
| 156 | + repo: 'mx-server' | 'mx-admin' |
| 157 | + title?: string |
| 158 | + }) => { |
| 159 | + version.value = params.version |
| 160 | + repo.value = params.repo |
| 161 | + title.value = params.title || '更新详情' |
| 162 | + showModal.value = true |
| 163 | + } |
| 164 | + |
| 165 | + const closeModal = () => { |
| 166 | + showModal.value = false |
| 167 | + } |
| 168 | + |
| 169 | + const Modal = () => ( |
| 170 | + <UpdateDetailModal |
| 171 | + show={showModal.value} |
| 172 | + onUpdate:show={(val: boolean) => showModal.value = val} |
| 173 | + version={version.value} |
| 174 | + repo={repo.value} |
| 175 | + title={title.value} |
| 176 | + /> |
| 177 | + ) |
| 178 | + |
| 179 | + return { |
| 180 | + openModal, |
| 181 | + closeModal, |
| 182 | + Modal, |
| 183 | + } |
| 184 | +} |
0 commit comments