This commit is contained in:
toom1996
2026-08-30 10:45:34 +08:00
parent a6724265ad
commit 9c3403a903
23 changed files with 284 additions and 508 deletions

View File

@ -23,8 +23,8 @@ database:
port: 3306 # env: DB_PORT
user: root # env: DB_USER
password: root # env: DB_PASSWORD(兼容 DB_PASS)
# 本地开发库名为 db;docker-compose 部署时用环境变量覆盖为 fashionadmin
name: db # env: DB_NAME
# 本地开发库名为 db_dev;docker-compose 部署时用环境变量覆盖为 fashionadmin
name: db_dev # env: DB_NAME
charset: utf8mb4
# GORM 日志级别:silent | error | warn | info
log_level: warn
@ -60,4 +60,18 @@ cors:
- Content-Type
- Authorization
- X-Requested-With
- X-Sign
- X-Sign-Ts
- X-Sign-Nonce
max_age: 86400 # 预检请求缓存秒数
# 公开接口「前端 JS 签名」:给 /runway-looks(列表)与 /brands 两个批量接口加请求签名校验,
# 识别「请求大概率由前端 JS 构造」、抬高 casual 爬虫的批量抓取成本。
# 安全定位:这是「提高成本」而非「加密」——密钥必须出现在前端 bundle,对浏览器可见;
# 有决心的爬虫可反编译 JS 复刻签名。与按 IP 限流配合才有效。
# - enabled: false 时不拦截(默认,灰度安全);true 时要求每个请求带 X-Sign 签名。
# - secret 必须与前端的 CLIENT_SIGN_SECRET 完全一致;生产经环境变量 CLIENT_SIGN_SECRET 注入随机长串。
client_sign:
enabled: false # env: CLIENT_SIGN_ENABLED(容器部署用环境变量开)
secret: "" # env: CLIENT_SIGN_SECRET
ttl_seconds: 30 # 签名时间戳容忍窗口(秒),防重放;env: CLIENT_SIGN_TTL