开源前加固认证与部署契约:加密随机 JWT、改密事务吊销、登录 CSRF,并禁止生产回落 localhost。
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -1,7 +1,14 @@
|
||||
// 认证 cookie 名(前后端必须严格一致):
|
||||
// 生产构建(HTTPS)启用 __Host- 前缀,浏览器强制 Secure + Path=/ + 无 Domain;
|
||||
// 后端按 !DevMode 同步启用(见 backend/service/auth.go ConfigureCookieNames)。
|
||||
const HOST_PREFIX = process.env.NODE_ENV === "production" ? "__Host-" : "";
|
||||
// 与后端 ConfigureCookieNames(!DevMode) 对齐——显式 DEV_MODE=true|1 禁用 __Host-;
|
||||
// 显式 DEV_MODE=false|0 启用;未设置时回退 NODE_ENV=production(官方镜像两者同时满足)。
|
||||
function hostCookiePrefix(): string {
|
||||
const dm = (process.env.DEV_MODE || "").trim().toLowerCase();
|
||||
if (dm === "true" || dm === "1") return "";
|
||||
if (dm === "false" || dm === "0") return "__Host-";
|
||||
return process.env.NODE_ENV === "production" ? "__Host-" : "";
|
||||
}
|
||||
|
||||
const HOST_PREFIX = hostCookiePrefix();
|
||||
|
||||
export const TOKEN_COOKIE = `${HOST_PREFIX}j13_token`;
|
||||
export const REFRESH_COOKIE = `${HOST_PREFIX}j13_refresh`;
|
||||
|
||||
Reference in New Issue
Block a user