⚓ Trial Login Fix · Operation Guide

ShipGod AI Free Trial Login Fix · 2026-08-18

1. Root Cause (verified in testing)

The code deployed on the live server auth-api.phpisGET POSTPOST JSON

trial.html POST
→
unknown action
→
login.html POST
→
old code that silently fell back to local → no prompts at all
Live TestingResultsConclusion
GET trial/login/register/checkAll normalThe API itself was running; accounts were being saved
POST JSON / POSTunknown actionPOST →
login.html / crew-home.html / index.html401The site-wide password gate blocked real visitors
trial.html / auth-api.php / upload.phpNow password-freeWhitelist had been added earlier

2. Fix Package Contents (4 files; overwrite-upload to the site root)

FileFix ContentConsequence If Not Uploaded
auth-api.phpPOST JSON + GETTrial login 100% failed (the core issue)
login.htmlServer messages like "wrong password / ship name not registered" display properly instead of silent failure; supports ?ship=auto-filling the ship nameClicking "Board" gave no feedback
trial.htmlAfter activation, the "Login Now" button auto-fills the ship nameTrial users had to type the ship name manually
sw.jsv3→v4 trial.html auth-api Service WorkerOld users kept loading the old login page

3. Baota Panel: Remove the Site-Wide Gate (Recommended)

The trial must be public, but dozens of workspace pages sit behind the gate; whitelisting them one by one is impractical.Recommended: make the whole site public and keep passwords only for admin pages.

  1. → → shipstrade.com.cn → Settings → Configuration Files
  2. server auth_basic& auth_basic_user_filetwo lines,user_file, then delete these two lines or add #comments
  3. server server_nameSecurity Hardening RulesPHP location PHP
# ===== PHP location =====
location = /ship-accounts.json { deny all; } # Account data (incl. plaintext passwords): download prohibited
location = /shared-notices.json { deny all; } # Notice data: direct download prohibited
location ~ ^/uploads/.*\.php$ { deny all; } # PHP webshell
  1. server }before) paste the content below,replace the path with the actual path copied in Step 2
# ===== Encrypt admin pages only (rest of site public) =====
location = /hq-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /orders-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /site-config-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /ship-mgmt-dept.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /ship-setup.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
  1. nginx → → Nginx
⚠ If you still want to keep the site-wide gate: you can also use location = /login.html { auth_basic off; }to allow pages one by one, but with 60+ workspace pages something will be missed and visitors will still hit 401 — strongly not recommended.
🔒 Why hardening is mandatory:Verified in testing: upload.phpPHPship-accounts.jsonit stores all ship names + plaintext passwords; without protection they will leak once the gate is removed;notices-api.phpthe publish API has no validation, so anyone could post notices. The three hardening rules take 5 minutes; skipping them leaves the site exposed.

4. Verify After Upload (Use an Incognito Window)

⚠ Your own browser has saved the gate password, so pages won't prompt 401 and you can't test the real visitor experience. Use Chrome/EdgeWiFi
  1. an incognito window https://shipstrade.com.cn/trial.html→ enter ship name + email → activate
  2. The page shows ship name + password + 7-day validity
  3. Click "🔐 Login to Workspace Now" → login pageShip name auto-filled
  4. Enter password → click "⛵ Board" → enter the workspace (no more 401, no more silent failure)
  5. Click through several role pages, folders and notices to confirm they work
✓ Acceptance: no 401 popups, no errors; failed logins show clear messages like "wrong password / ship name not registered".

5. Wrap-Up

ItemDescription
Clean up test accountsDuring troubleshooting, test accounts were created on the server ship-accounts.jsoncreated ZZTEST0818(trial; auto-expires in 7 days) and ZZTEST4basic
Clean up test filesDuring the security check, files were uploaded /uploads/test/sec-check/sg_security_test.txt; please delete the entire /uploads/test/directory
Old user cachesw.js v4 APK
Password-free config already presentconfig-api.php / coze fastcgi