API 文档

所有接口前缀 /api。管理后台接口以 /api/admin 开头,需 Session 登录(POST /api/admin/login)+ CSRF Token。

认证说明:用户接口使用 Bearer Token(JWT),在请求头中传入 Authorization: Bearer <token>。管理后台使用 Session 登录(POST /api/admin/login)+ CSRF Token。
认证与用户
POST/api/auth/send-code发送短信验证码

请求体

{"phone": "13800138000"}

响应

{"ok": true, "message": "验证码已发送"}

验证码 5 分钟有效。同一手机号 60 秒内限发 1 次。

POST/api/auth/verify-login验证码登录

请求体

{"phone": "13800138000", "code": "123456"}

响应

{"token": "eyJ...", "phone": "13800138000", "userId": 1}
GET/api/user/profile获取用户信息

请求头

Authorization: Bearer <token>

响应

{"id": 1, "phone": "138****8000", "created_at": 1717603200}
GET/api/user/serials用户序列号列表

响应

{"serials": [{"serial": "RAD-XXXX-XXXX-XXXX-XXXX", "product": "recording", "plan": "月付", "status": "active", "expires_at": 1720000000}]}
GET/api/user/payment-orders支付订单历史

响应

{"orders": [{"id": 1, "plan": "recording_monthly", "amount": 29.9, "status": "approved", "created_at": 1717603200}]}
POST/api/user/change-phone更换手机号

请求体

{"currentPhone": "13800138000", "currentCode": "111111", "newPhone": "13900139000", "newCode": "222222"}

响应

{"ok": true, "token": "eyJ..."}
POST/api/auth/activate-trial激活免费试用

请求头

Authorization: Bearer <token>

响应

{"ok": true, "serial": "RAD-TRIAL-XXXX", "expiresAt": 1718208000}
许可激活
POST/api/activate激活序列号

请求体

{"serial": "RAD-XXXX-XXXX-XXXX-XXXX", "fingerprint": "mac-fingerprint-hash", "hostname": "My-MacBook"}

响应

{"ok": true, "token": "...", "expiresAt": 1720000000, "plan": "monthly"}
POST/api/heartbeat心跳验证

请求体

{"token": "<license-token>"}

响应

{"ok": true, "serverTime": 1717603200, "expiresAt": 1720000000}
视频管理
GET/api/videos视频列表

查询参数

?category=install|tutorial  (可选,筛选分类)

响应

{"videos": [{"id": 1, "title": "安装教程", "filename": "xxx.mp4", "category": "install", "file_size": 10485760, "created_at": 1717603200}]}
POST/api/videos/upload上传视频

Content-Type

multipart/form-data

表单字段

video: File (必填,最大 500MB)
title: String (选填)
category: String (选填:install|tutorial)
description: String (选填)

响应

{"ok": true, "filename": "1717603200-abc123.mp4"}
PUT/api/videos/:id编辑视频信息

请求体

{"title": "新标题", "category": "tutorial", "description": "描述"}

响应

{"ok": true}
DELETE/api/videos/:id删除视频

权限

需视频上传者或管理员

响应

{"ok": true}
支付系统
POST/api/pay/create创建支付订单

请求体

{"plan": "recording_monthly", "amount": 29.9}

响应

{"ok": true, "outTradeNo": "RAD..."}
GET/api/pay/status/:outTradeNo查询支付状态

响应

{"status": "approved"|"pending"|"paid", "serial": "RAD-..."}
管理后台
GET/api/admin/licenses序列号列表

查询参数

?page=1&status=all|active|expired|disabled&search=<关键词>

响应

{"rows": [...], "total": 42, "page": 1, "limit": 50}
POST/api/admin/licenses生成序列号

请求体

{"count": 1, "product": "recording", "plan": "月付", "durationDays": 30}
POST/api/admin/disable禁用序列号

请求体

{"serial": "RAD-..."}
POST/api/admin/extend续期序列号

请求体

{"serial": "RAD-...", "days": 30}
POST/api/admin/unbind解绑机器

请求体

{"serial": "RAD-...", "fingerprint": "mac-hash"}
POST/api/admin/batch-disable批量禁用

请求体

{"serials": ["RAD-...", "RAD-..."]}

响应

{"ok": true, "count": 2}
POST/api/admin/batch-extend批量续期

请求体

{"serials": ["RAD-...", "RAD-..."], "days": 30}
GET/api/admin/export导出 CSV

查询参数

?status=all&search=<关键词>

响应

Content-Type: text/csv
GET/api/admin/licenses/:serial序列号详情

响应

{"serial": "...", "machines": [...], "auditLogs": [...]}
GET/api/admin/expiring即将到期列表

查询参数

?days=7
GET/api/admin/anomalies异常检测

响应

{"anomalies": [{"type": "多设备激活", "severity": "high", "detail": "..."}]}
健康检查
GET/api/health公开健康检查

响应

{"status": "ok", "time": 1717603200}
GET/api/admin/health服务器监控

请求头

X-Admin-Password: <password>

响应

{"uptime": 86400, "memoryMB": 128, "totalRequests": 5432, "wsClients": 1}
POST/api/admin/login管理后台登录

请求体

{"password": "admin-password"}

响应

{"ok": true, "csrfToken": "..."}

登录成功后设置 session cookie,返回 CSRF token 用于后续写操作。登录限流 5 次/15 分钟。

POST/api/admin/logout管理后台退出

响应

{"ok": true}
GET/api/admin/export/users导出用户 CSV

响应

Content-Type: text/csv

导出字段:ID、手机号、用户名、关联序列号、注册时间

GET/api/admin/export/payments导出支付订单 CSV

响应

Content-Type: text/csv

导出字段:订单ID、手机号、套餐、金额、订单号、交易号、状态、序列号、创建时间

GET/api/user/notifications用户通知列表

响应

{"notifications": [{"id": 1, "title": "...", "type": "welcome", "read": 0, "created_at": 1717603200}]}
POST/api/user/notifications/read标记通知已读

响应

{"ok": true}
GET/api/user/referrals推荐奖励统计

响应

{"invited": 3, "completed": 1, "rewardHours": 300, "inviteLink": "https://radarrec.com/?ref=1"}
PUT/api/user/profile修改用户名

请求体

{"username": "新用户名"}

响应

{"ok": true, "username": "新用户名"}
POST/api/pay/submit提交手动交易单号

请求体

{"outTradeNo": "RAD-...", "transactionId": "WX-..."}

响应

{"ok": true}
POST/api/admin/notify/version版本更新广播

请求体

{"version": "1.2.0", "changes": "修复了录音打标 Bug"}
POST/api/admin/notify/feature新功能广播

请求体

{"title": "自动对轨", "description": "支持一键音频对轨"}
POST/api/admin/notify/announce系统公告广播

请求体

{"content": "系统将于今晚 22:00 维护"}
POST/api/verify-token令牌验证(服务端终裁)

请求体

{"token": "...", "serial": "RAD-...", "fingerprint": "...", "timestamp": 1717603200}

响应

{"valid": true}

供 Swift 二进制 SSL Pinning 调用。防重放:时间戳 30s 窗口。