refactor: 配置安全加固-从TOML移除密钥+去除死代码+统一端口
P0: 从config/production.toml和config/development.toml移除wechat_secret/jwt_secret
这些密钥现在仅通过.env(EnvironmentFile)加载,不再进入Git历史
config.rs: 新增直接环境变量名回退(JWT_SECRET而非仅APP_JWT_SECRET)
P1: - 移除config.rs中的server_ports字段(死代码,未被任何代码使用)
- 简化main.rs端口fallback: 生产环境仅4433,开发环境仅8080/3000
- .env.example版本号0.2.3→0.3.0
Docs: - AGENTS.md测试域名xmclassmate.top/dev→dev.xmclassmate.top
This commit is contained in:
@@ -692,7 +692,7 @@ const CURRENT_ENV: 'development' | 'production' = 'production'; // 发布前切
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
# 设置测试域名
|
# 设置测试域名
|
||||||
export TEST_DOMAIN="https://xmclassmate.top/dev" # 开发环境
|
export TEST_DOMAIN="https://dev.xmclassmate.top" # 开发环境
|
||||||
export TEST_DOMAIN="https://xmclassmate.top" # 生产环境
|
export TEST_DOMAIN="https://xmclassmate.top" # 生产环境
|
||||||
|
|
||||||
# 运行测试
|
# 运行测试
|
||||||
|
|||||||
@@ -8,4 +8,3 @@ rust_log = "debug"
|
|||||||
environment = "development"
|
environment = "development"
|
||||||
free_user_data_limit = 100
|
free_user_data_limit = 100
|
||||||
server_host = "0.0.0.0"
|
server_host = "0.0.0.0"
|
||||||
server_ports = [8080, 3000, 8000, 8888]
|
|
||||||
@@ -1,6 +1,5 @@
|
|||||||
database_url = "postgres://milkydata:44n6FdB8CdDAk5rk@127.0.0.1:5432/milkydata_dev"
|
database_url = "postgres://milkydata:44n6FdB8CdDAk5rk@127.0.0.1:5432/milkydata_dev"
|
||||||
wechat_appid = "wx5b00eb90621802f7"
|
wechat_appid = "wx5b00eb90621802f7"
|
||||||
wechat_secret = "494efc513faa310bfba588bda2849bfd"
|
|
||||||
jwt_secret = "dev-only-secret-change-in-production"
|
jwt_secret = "dev-only-secret-change-in-production"
|
||||||
ssl_key_path = ""
|
ssl_key_path = ""
|
||||||
ssl_cert_path = ""
|
ssl_cert_path = ""
|
||||||
@@ -8,4 +7,3 @@ rust_log = "debug"
|
|||||||
environment = "development"
|
environment = "development"
|
||||||
free_user_data_limit = 100
|
free_user_data_limit = 100
|
||||||
server_host = "0.0.0.0"
|
server_host = "0.0.0.0"
|
||||||
server_ports = [8080, 3000, 8000, 8888]
|
|
||||||
@@ -1,11 +1,8 @@
|
|||||||
database_url = "postgres://milkydata:44n6FdB8CdDAk5rk@154.37.213.24:5432/milkydata"
|
database_url = "postgres://milkydata:44n6FdB8CdDAk5rk@154.37.213.24:5432/milkydata"
|
||||||
wechat_appid = "wx5b00eb90621802f7"
|
wechat_appid = "wx5b00eb90621802f7"
|
||||||
wechat_secret = "494efc513faa310bfba588bda2849bfd"
|
|
||||||
jwt_secret = "your_super_secret_key"
|
|
||||||
ssl_key_path = "/etc/ssl/private/private.key"
|
ssl_key_path = "/etc/ssl/private/private.key"
|
||||||
ssl_cert_path = "/etc/ssl/certs/full_chain.pem"
|
ssl_cert_path = "/etc/ssl/certs/full_chain.pem"
|
||||||
rust_log = "info"
|
rust_log = "info"
|
||||||
environment = "production"
|
environment = "production"
|
||||||
free_user_data_limit = 20
|
free_user_data_limit = 20
|
||||||
server_host = "0.0.0.0"
|
server_host = "0.0.0.0"
|
||||||
server_ports = [4433, 8443, 8080, 3000, 8000, 8888]
|
|
||||||
@@ -17,8 +17,6 @@ pub struct AppConfig {
|
|||||||
pub environment: String,
|
pub environment: String,
|
||||||
pub free_user_data_limit: i32,
|
pub free_user_data_limit: i32,
|
||||||
pub server_host: String,
|
pub server_host: String,
|
||||||
#[serde(rename = "server_ports")]
|
|
||||||
pub server_ports: Vec<u16>,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
impl AppConfig {
|
impl AppConfig {
|
||||||
@@ -57,16 +55,17 @@ impl AppConfig {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 3. 从环境变量加载(最高优先级)
|
// 3. 从环境变量加载(最高优先级)
|
||||||
|
// 支持两种前缀:APP_*(推荐)和直接变量名(兼容 systemd EnvironmentFile)
|
||||||
if let Ok(val) = std::env::var("APP_DATABASE_URL") {
|
if let Ok(val) = std::env::var("APP_DATABASE_URL") {
|
||||||
settings.insert("database_url".into(), toml::Value::String(val));
|
settings.insert("database_url".into(), toml::Value::String(val));
|
||||||
}
|
}
|
||||||
if let Ok(val) = std::env::var("APP_JWT_SECRET") {
|
if let Ok(val) = std::env::var("APP_JWT_SECRET").or_else(|_| std::env::var("JWT_SECRET")) {
|
||||||
settings.insert("jwt_secret".into(), toml::Value::String(val));
|
settings.insert("jwt_secret".into(), toml::Value::String(val));
|
||||||
}
|
}
|
||||||
if let Ok(val) = std::env::var("APP_WECHAT_APPID") {
|
if let Ok(val) = std::env::var("APP_WECHAT_APPID").or_else(|_| std::env::var("WECHAT_APPID")) {
|
||||||
settings.insert("wechat_appid".into(), toml::Value::String(val));
|
settings.insert("wechat_appid".into(), toml::Value::String(val));
|
||||||
}
|
}
|
||||||
if let Ok(val) = std::env::var("APP_WECHAT_SECRET") {
|
if let Ok(val) = std::env::var("APP_WECHAT_SECRET").or_else(|_| std::env::var("WECHAT_SECRET")) {
|
||||||
settings.insert("wechat_secret".into(), toml::Value::String(val));
|
settings.insert("wechat_secret".into(), toml::Value::String(val));
|
||||||
}
|
}
|
||||||
if let Ok(val) = std::env::var("APP_RUST_LOG") {
|
if let Ok(val) = std::env::var("APP_RUST_LOG") {
|
||||||
|
|||||||
@@ -183,10 +183,10 @@ async fn main() -> std::io::Result<()> {
|
|||||||
info!("Attempting to start server...");
|
info!("Attempting to start server...");
|
||||||
|
|
||||||
let is_production = std::env::var("APP_ENV").unwrap_or_else(|_| "development".into()) == "production";
|
let is_production = std::env::var("APP_ENV").unwrap_or_else(|_| "development".into()) == "production";
|
||||||
let ports = if is_production {
|
let ports: Vec<u16> = if is_production {
|
||||||
vec![4433, 8443, 8080, 3000, 8000, 8888]
|
vec![4433]
|
||||||
} else {
|
} else {
|
||||||
vec![8080, 3000, 8000, 8888, 4433, 8443]
|
vec![8080, 3000]
|
||||||
};
|
};
|
||||||
let mut server: Option<
|
let mut server: Option<
|
||||||
Pin<Box<dyn std::future::Future<Output = std::io::Result<()>> + Unpin>>,
|
Pin<Box<dyn std::future::Future<Output = std::io::Result<()>> + Unpin>>,
|
||||||
|
|||||||
Reference in New Issue
Block a user