refactor: 移除 2FA 功能与三个冗余依赖

2FA 早已是死代码:TOTP 相关端点标注为前端未调用,前端唯一的
two_factor_auth 是硬编码 false,没有任何入口能打开它。

- 删除 TwoFactorAuthAPI、CheckTFARequiredAPI、_totp* 辅助函数、
  TwoFactorAuthCodeSerializer 及各 serializer 的 tfa_code 字段
- 删除管理端写 two_factor_auth/tfa_token 的分支。登录已不再校验
  TOTP,若保留写入路径,置 True 会变成静默的安全降级
- 删除 User.two_factor_auth / tfa_token 字段(迁移 0009)
- 移除 django-dbconn-retry:仅挂在 INSTALLED_APPS,代码零引用。
  DATABASES 未配置 CONN_MAX_AGE(默认 0),本就没有持久连接需要
  重连修复。要开持久连接用 Django 自带的 CONN_HEALTH_CHECKS
- requests 换成 httpx(openai 已经引入):删除废弃的
  ReleaseNotesAPI,judge dispatcher 显式传 timeout=None 以保持
  requests 原本的无超时行为,判题请求是同步等结果的

依赖净减 5 个:otpauth、qrcode、requests、charset-normalizer、
django-dbconn-retry

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-05 23:00:45 -06:00
parent 7be5975d88
commit 989b33d827
13 changed files with 56 additions and 363 deletions

View File

@@ -4,7 +4,7 @@ import logging
from datetime import timedelta
from urllib.parse import urljoin
import requests
import httpx
from django.db import IntegrityError, transaction
from django.db.models import F
from django.utils import timezone
@@ -73,7 +73,8 @@ class DispatcherBase(object):
if data:
kwargs["json"] = data
try:
return requests.post(url, **kwargs).json()
# timeout=None 保持与原 requests 实现一致:判题请求是同步等结果的,不能被默认超时打断
return httpx.post(url, timeout=None, **kwargs).json()
except Exception as e:
logger.exception(e)