v1.2.61 - 安全修复:CORS限制+SECRET_KEY强制环境变量

This commit is contained in:
甲辰生产 2026-04-08 13:35:18 +08:00
parent 309dd056c6
commit eb64ce3d8c
2 changed files with 6 additions and 3 deletions

View File

@ -11,7 +11,9 @@ from app.core.database import SessionLocal
from app.models.models import User from app.models.models import User
# 配置 # 配置
SECRET_KEY = os.getenv("SECRET_KEY", "your-secret-key-change-in-production") SECRET_KEY = os.getenv("SECRET_KEY")
if not SECRET_KEY:
raise ValueError("SECRET_KEY environment variable is not set. Please configure it in production!")
ALGORITHM = "HS256" ALGORITHM = "HS256"
ACCESS_TOKEN_EXPIRE_MINUTES = int(os.getenv("ACCESS_TOKEN_EXPIRE_MINUTES", "10080")) # 7天 ACCESS_TOKEN_EXPIRE_MINUTES = int(os.getenv("ACCESS_TOKEN_EXPIRE_MINUTES", "10080")) # 7天

View File

@ -52,10 +52,11 @@ app = FastAPI(
# 设置全局错误处理器 # 设置全局错误处理器
setup_error_handlers(app) setup_error_handlers(app)
# CORS 配置 # CORS 配置 - 生产环境限制域名
ALLOWED_ORIGINS = os.getenv("ALLOWED_ORIGINS", "http://47.103.29.111,http://120.55.81.21,https://socoolbot.com").split(",")
app.add_middleware( app.add_middleware(
CORSMiddleware, CORSMiddleware,
allow_origins=["*"], # 生产环境应该限制域名 allow_origins=ALLOWED_ORIGINS,
allow_credentials=True, allow_credentials=True,
allow_methods=["*"], allow_methods=["*"],
allow_headers=["*"], allow_headers=["*"],