开源前加固认证与部署契约:加密随机 JWT、改密事务吊销、登录 CSRF,并禁止生产回落 localhost。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-23 02:07:34 +08:00
parent 6f054a903c
commit 3b550f2124
24 changed files with 372 additions and 355 deletions

View File

@@ -1,8 +1,17 @@
import type { NextConfig } from "next";
// 后端地址:开发环境兜底 localhost:3001,生产部署必须显式配置 BACKEND_URL
// 后端地址:开发可兜底 localhost:3001;生产构建必须显式 BACKEND_URL(禁止静默烤进 localhost)
const isProd = process.env.NODE_ENV === "production";
const API_TARGET =
process.env.BACKEND_URL || process.env.NEXT_PUBLIC_API_URL || "http://localhost:3001";
process.env.BACKEND_URL ||
process.env.NEXT_PUBLIC_API_URL ||
(isProd ? "" : "http://localhost:3001");
if (!API_TARGET) {
throw new Error(
"生产构建必须设置 BACKEND_URL(例如 Docker 内 http://api:3001),禁止回落 localhost"
);
}
const nextConfig: NextConfig = {
// 官方 Docker 运行时:最小产物,不含完整 node_modules。next dev 忽略此项。