|
1 | 1 | # Schwab Token Auto Refresher |
2 | 2 |
|
| 3 | +[English](#english) | [中文](#中文) |
| 4 | + |
| 5 | +--- |
| 6 | + |
| 7 | +<a id="english"></a> |
| 8 | +## English |
| 9 | + |
3 | 10 | [](LICENSE) |
4 | 11 | [](https://nodejs.org/) |
5 | 12 | [](https://playwright.dev/) |
@@ -88,3 +95,71 @@ Notes: |
88 | 95 |
|
89 | 96 | ## 📄 License |
90 | 97 | Distributed under the MIT License. See `LICENSE` for more information. |
| 98 | + |
| 99 | +--- |
| 100 | + |
| 101 | +<a id="中文"></a> |
| 102 | +## 中文 |
| 103 | + |
| 104 | +用于自动刷新 Charles Schwab API refresh token 的工具。它在 GitHub-hosted runner(`ubuntu-latest`)上运行官方 Google Chrome,自动完成 OAuth consent flow,并把刷新后的凭据同步到 Google Cloud Secret Manager。 |
| 105 | + |
| 106 | +## 功能 |
| 107 | + |
| 108 | +- **GitHub-hosted 运行**:直接使用 GitHub runner,不需要维护私有 VPS。 |
| 109 | +- **官方 Chrome**:动态安装 retail Google Chrome `.deb`,提高浏览器兼容性。 |
| 110 | +- **Stealth 自动化**:通过 `playwright-extra` 和 stealth 插件模拟正常浏览器行为。 |
| 111 | +- **虚拟显示**:在 CI 中使用 `xvfb-run` 支持 headed browser 交互。 |
| 112 | +- **安全同步**:刷新后的 token 直接写入 Google Cloud Secret Manager,不写入仓库。 |
| 113 | +- **隔离日志**:成功时间戳提交到独立 `logs` 分支,避免污染主分支历史。 |
| 114 | + |
| 115 | +## 设置 |
| 116 | + |
| 117 | +如果你 fork 了这个仓库,需要在 **Settings > Secrets and variables > Actions** 中配置: |
| 118 | + |
| 119 | +| Secret Name | 说明 | |
| 120 | +| :--- | :--- | |
| 121 | +| `SCHWAB_USERNAME` | Schwab 登录 ID | |
| 122 | +| `SCHWAB_PASSWORD` | Schwab 登录密码 | |
| 123 | +| `SCHWAB_TOTP_SECRET` | 2FA/MFA Base32 secret | |
| 124 | +| `SCHWAB_API_KEY` | Schwab Developer App Client ID | |
| 125 | +| `SCHWAB_APP_SECRET` | Schwab Developer App Client Secret | |
| 126 | +| `GCP_SA_KEY` | 具备 Secret Manager 权限的 GCP Service Account JSON key | |
| 127 | +| `SCHWAB_PROXY_URL` | 可选的认证 HTTP/HTTPS 代理 URL,用于让 Schwab 浏览器/API 流量走住宅或家庭出口 | |
| 128 | + |
| 129 | +这些值属于配置而非凭据,更适合放在 **GitHub Variables**: |
| 130 | + |
| 131 | +| Variable Name | 说明 | |
| 132 | +| :--- | :--- | |
| 133 | +| `GCP_PROJECT_ID` | Google Cloud Project ID | |
| 134 | +| `GCP_SECRET_ID` | Secret Manager 中的 secret 名称 | |
| 135 | +| `SCHWAB_REDIRECT_URI` | Schwab app 注册的 redirect URI | |
| 136 | + |
| 137 | +## 启用 workflow |
| 138 | + |
| 139 | +1. 打开仓库的 **Actions** tab。 |
| 140 | +2. 选择 **Schwab Token Auto Refresher**。 |
| 141 | +3. 点击 **Enable workflow**。 |
| 142 | +4. 可选:用 **Run workflow** 手工触发一次,验证配置。 |
| 143 | + |
| 144 | +## 可选代理 |
| 145 | + |
| 146 | +如果 Schwab 从住宅网络访问更稳定,可以配置 `SCHWAB_PROXY_URL`,让 Schwab 浏览器流程和 token exchange 请求走认证代理。默认情况下不使用代理。 |
| 147 | + |
| 148 | +注意: |
| 149 | + |
| 150 | +- 路由器公网 IP 本身不是代理。 |
| 151 | +- 不要把 OpenWrt/LuCI 管理界面暴露到公网。 |
| 152 | +- 需要单独部署一个 GitHub Actions 可访问的 HTTP/HTTPS proxy service。 |
| 153 | +- 只有 Schwab 自动化流量走代理;依赖安装、GitHub 和 GCP 操作仍走 runner 默认出口。 |
| 154 | + |
| 155 | +## 架构 |
| 156 | + |
| 157 | +1. GitHub Actions schedule 每 3 天触发一次。 |
| 158 | +2. Runner 安装 Google Chrome stable,并初始化 `xvfb` 虚拟显示。 |
| 159 | +3. Playwright-stealth 完成 OAuth 流程、输入凭据、生成 TOTP,并截获 redirect code。 |
| 160 | +4. 工具用 code 换取 token,并更新 GCP Secret Manager。 |
| 161 | +5. 成功时间戳写入 `logs` 分支。 |
| 162 | + |
| 163 | +## 许可证 |
| 164 | + |
| 165 | +本项目使用 MIT License。详见 `LICENSE`。 |
0 commit comments