开源前加固认证与部署契约:加密随机 JWT、改密事务吊销、登录 CSRF,并禁止生产回落 localhost。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-23 02:07:34 +08:00
parent 6f054a903c
commit 3b550f2124
24 changed files with 372 additions and 355 deletions

View File

@@ -22,8 +22,9 @@ POSTGRES_USER=jiang13
POSTGRES_PASSWORD=change-me
POSTGRES_DB=jiang13
# 生产必须显式设置。留空则首次启动写入 data/.jwt_secret(依赖 appdata volume)。
JWT_SECRET=change-me-to-a-long-random-string
# 生产必须显式设置 ≥32 字符强随机(openssl rand -base64 32)。
# 占位值 change-me / 过短密钥会被拒绝启动;也可留空由 data/.jwt_secret 自动生成。
JWT_SECRET=
# 正式站点 origin,生产使用 HTTPS;邮件 / Canonical / Sitemap 共用
# 32 字节随机值的标准 Base64;不填写时禁止保存邮件/S3凭据。独立备份,禁止提交真实密钥。

View File

@@ -15,6 +15,7 @@ ARG VERSION=dev
ARG BACKEND_URL=http://api:3001
ENV NEXT_TELEMETRY_DISABLED=1 \
NODE_ENV=production \
DEV_MODE=false \
NEXT_PUBLIC_APP_VERSION=${VERSION} \
BACKEND_URL=${BACKEND_URL}
RUN npm run build
@@ -22,6 +23,7 @@ RUN npm run build
FROM node:22-bookworm-slim AS runner
WORKDIR /app
ENV NODE_ENV=production \
DEV_MODE=false \
PORT=3000 \
HOSTNAME=0.0.0.0 \
NEXT_TELEMETRY_DISABLED=1 \

View File

@@ -67,6 +67,7 @@ services:
BACKEND_URL: http://api:3001
SITE_URL: ${SITE_URL:-https://localhost}
NODE_ENV: production
DEV_MODE: "false"
PORT: "3000"
HOSTNAME: 0.0.0.0
ports: