开源前加固认证与部署契约:加密随机 JWT、改密事务吊销、登录 CSRF,并禁止生产回落 localhost。
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -21,10 +21,19 @@ export type { FooterLink, FooterLinksAlign };
|
||||
// API 基础配置
|
||||
// 注意:客户端请求使用相对路径 /api/*,走 Next.js rewrite 代理到后端,
|
||||
// 这样浏览器视为同源,Cookie 自动携带,无需处理 CORS。
|
||||
// SSR/middleware 直连后端:优先服务端专用 BACKEND_URL(边缘部署必须显式配置,
|
||||
// localhost 兜底只在本地开发有效),回退到 NEXT_PUBLIC_API_URL。
|
||||
const API_BASE =
|
||||
process.env.BACKEND_URL || process.env.NEXT_PUBLIC_API_URL || "http://localhost:3001";
|
||||
// SSR/middleware 直连后端:优先 BACKEND_URL;生产禁止静默回落 localhost。
|
||||
const API_BASE = (() => {
|
||||
const fromEnv =
|
||||
process.env.BACKEND_URL || process.env.NEXT_PUBLIC_API_URL || "";
|
||||
if (fromEnv) return fromEnv;
|
||||
if (process.env.NODE_ENV === "production") {
|
||||
if (typeof window === "undefined") {
|
||||
throw new Error("生产环境必须设置 BACKEND_URL(SSR 直连后端)");
|
||||
}
|
||||
return "";
|
||||
}
|
||||
return "http://localhost:3001";
|
||||
})();
|
||||
|
||||
// SSR 请求超时:后端不可用时快速降级为游客视图,不阻塞页面渲染
|
||||
const SSR_TIMEOUT_MS = 8000;
|
||||
|
||||
Reference in New Issue
Block a user