开源前加固认证与部署契约:加密随机 JWT、改密事务吊销、登录 CSRF,并禁止生产回落 localhost。
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -6,9 +6,14 @@
|
||||
NEXT_PUBLIC_API_URL=http://localhost:3001
|
||||
|
||||
# 仅服务端可见(middleware 与 SSR 优先使用)。
|
||||
# 部署到 Cloudflare Workers 等边缘环境时【必须】显式配置为后端 HTTPS 地址,
|
||||
# 边缘运行时不存在 localhost,留空会导致 SSR 登录态轮转直接放行失效。
|
||||
# BACKEND_URL=https://your-backend.example.com
|
||||
# 生产构建【必须】显式配置;缺省会直接失败,禁止烤进 localhost。
|
||||
# Docker 官方镜像构建期注入 http://api:3001。
|
||||
# BACKEND_URL=http://localhost:3001
|
||||
|
||||
# 与后端 DEV_MODE 对齐:true 时 cookie 无 __Host- 前缀。
|
||||
# 本地 next start 对着 DEV_MODE=true 的 Go 时请设为 true,避免 cookie 名分叉。
|
||||
# 官方 Docker 写死 false。
|
||||
DEV_MODE=true
|
||||
|
||||
# 可选。官方 Docker 构建会写入与仓库根 VERSION 相同的值;本地 dev 可不设。
|
||||
# NEXT_PUBLIC_APP_VERSION=0.1.0
|
||||
|
||||
Reference in New Issue
Block a user