chore: add and update gitignore rules for project files
add a comprehensive gitignore file to exclude unnecessary files like dependencies, runtime data, uploads, local configs and debug temporary files
This commit is contained in:
+147
-1
@@ -7,7 +7,9 @@ const Database = require('better-sqlite3')
|
||||
const crypto = require('crypto')
|
||||
|
||||
// ===== 从 ~/Toolbox_local_creds.env.local 加载变量到 process.env =====
|
||||
// 所有模块的 process.env.XXX fallback 依赖此加载器
|
||||
// ★ 规则:所有密码、密钥、Token、用户名等高危内容,禁止硬编码在源码里。
|
||||
// 一律放在 ~/Toolbox_local_creds.env.local 中,在此处自动加载到 process.env
|
||||
// 各模块通过 process.env.XXX 读取,不要直接 import 或 require 凭证。
|
||||
// 优先级:已存在的 process.env > env 文件 > 模块内 '' fallback
|
||||
try {
|
||||
const os = require('os')
|
||||
@@ -76,6 +78,8 @@ const plantHome = require('./plant_home')
|
||||
const globalNews = require('./global_news')
|
||||
const boxBackup = require('./box_backup')
|
||||
const yuanzhupai = require('./yuanzhupai')
|
||||
const dataGateway = require('./data_gateway')
|
||||
const ossFileCabinet = require('./oss_file_cabinet')
|
||||
yuanzhupai.initDb()
|
||||
|
||||
const app = express()
|
||||
@@ -1335,6 +1339,7 @@ const mapSystemIdToUrl = (systemId) => {
|
||||
'FitnessDiary': '/tools/fitness_diary',
|
||||
'Tools-doc_cloud_keeper': '/tools/doc_cloud_keeper',
|
||||
'Tools-yuanzhupai': '/tools/yuanzhupai',
|
||||
'Tools-oss_file_cabinet': '/tools/oss_file_cabinet',
|
||||
'Tools-plant_home': '/tools/plant_home',
|
||||
'Tools-apple_watch': '/tools/apple_watch',
|
||||
'Tools-private_clipboard': '/tools/private_clipboard',
|
||||
@@ -2078,6 +2083,145 @@ app.use('/api/private_clipboard', (req, res, next) => {
|
||||
return res.status(503).json({ ok: false, error: 'service_not_ready' })
|
||||
})
|
||||
|
||||
const OSS_FILE_CABINET_AUTH_COOKIE = 'oss_file_cabinet_gate'
|
||||
const readOssFileCabinetAuthConfig = () => {
|
||||
try {
|
||||
const p = path.join(process.cwd(), 'public', 'tools', 'oss_file_cabinet', 'auth_config.json')
|
||||
if (fs.existsSync(p)) {
|
||||
const cfg = JSON.parse(fs.readFileSync(p, 'utf-8'))
|
||||
if (cfg && typeof cfg === 'object') return cfg
|
||||
}
|
||||
} catch {}
|
||||
return {}
|
||||
}
|
||||
const readOssFileCabinetJwk = () => {
|
||||
try {
|
||||
const p = path.join(process.cwd(), 'config', 'oss_file_cabinet.jwk.json')
|
||||
if (fs.existsSync(p)) return JSON.parse(fs.readFileSync(p, 'utf-8'))
|
||||
} catch {}
|
||||
return { kty: 'RSA', n: '', e: '' }
|
||||
}
|
||||
const getOssFileCabinetCookieName = () => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
const n = String(cfg.cookieName || '')
|
||||
if (n) return n
|
||||
} catch {}
|
||||
return OSS_FILE_CABINET_AUTH_COOKIE
|
||||
}
|
||||
const getOssFileCabinetMaxAge = () => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
const days = Number(cfg.max_age_days || 0)
|
||||
if (Number.isFinite(days) && days > 0) return Math.min(days, 365) * 24 * 3600 * 1000
|
||||
} catch {}
|
||||
return 30 * 24 * 3600 * 1000
|
||||
}
|
||||
const getOssFileCabinetGuidConfig = () => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
const keyRaw = String(cfg.guidParam || cfg.guid_param || 'guid').trim()
|
||||
const valueRaw = String(cfg.guidValue || cfg.guid_value || '').trim()
|
||||
return { key: keyRaw || 'guid', value: valueRaw }
|
||||
} catch { return { key: 'guid', value: '' } }
|
||||
}
|
||||
const hasValidOssFileCabinetGuid = (req) => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
if (cfg.enable_auth === false) return false
|
||||
const { key, value } = getOssFileCabinetGuidConfig()
|
||||
if (!value) return false
|
||||
const q = req && req.query ? req.query : {}
|
||||
const raw = q[key]
|
||||
if (raw === undefined || raw === null) return false
|
||||
const incoming = Array.isArray(raw) ? String(raw[0] || '') : String(raw)
|
||||
return incoming === value
|
||||
} catch { return false }
|
||||
}
|
||||
const hasOssFileCabinetAuth = (req) => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
if (cfg.enable_auth === false) return true
|
||||
const cookies = parseCookie(req.headers.cookie || '')
|
||||
const name = getOssFileCabinetCookieName()
|
||||
return cookies[name] === '1'
|
||||
} catch { return false }
|
||||
}
|
||||
const isOssFileCabinetForceGuid = () => {
|
||||
try {
|
||||
const cfg = readOssFileCabinetAuthConfig()
|
||||
if (cfg.enable_auth === false) return false
|
||||
if (Object.prototype.hasOwnProperty.call(cfg, 'requireGuid')) return !!cfg.requireGuid
|
||||
if (Object.prototype.hasOwnProperty.call(cfg, 'require_guid')) return !!cfg.require_guid
|
||||
return true
|
||||
} catch { return true }
|
||||
}
|
||||
app.get('/tools/oss_file_cabinet', (req, res, next) => {
|
||||
setNoCache(res)
|
||||
try {
|
||||
const forceGuid = isOssFileCabinetForceGuid()
|
||||
if (hasOssFileCabinetAuth(req)) return next()
|
||||
const guidKey = getOssFileCabinetGuidConfig().key
|
||||
const hasGuidInput = req && req.query && Object.prototype.hasOwnProperty.call(req.query, guidKey)
|
||||
if (hasValidOssFileCabinetGuid(req)) {
|
||||
const maxAgeOfc = getOssFileCabinetMaxAge()
|
||||
const cookieName = getOssFileCabinetCookieName()
|
||||
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
|
||||
return res.redirect('/tools/oss_file_cabinet/index.html')
|
||||
}
|
||||
if (hasGuidInput) return res.status(401).send('未授权')
|
||||
const token = String(req.query.token || '')
|
||||
if (!token) {
|
||||
if (forceGuid) return res.status(401).send('未授权')
|
||||
return next()
|
||||
}
|
||||
const payload = verifyJwtWithKeys(token, jwkKeys(readOssFileCabinetJwk()))
|
||||
if (!payload) return res.status(401).send('未授权')
|
||||
{
|
||||
const iss = String(payload.iss || '')
|
||||
const navIss = getNavIssFromFlags()
|
||||
if (iss === navIss && !audMatch(payload, 'Tools-oss_file_cabinet')) return res.status(401).send('未授权')
|
||||
}
|
||||
const maxAgeOfc = getOssFileCabinetMaxAge()
|
||||
const cookieName = getOssFileCabinetCookieName()
|
||||
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
|
||||
return res.redirect('/tools/oss_file_cabinet/index.html')
|
||||
} catch { return res.status(401).send('未授权') }
|
||||
})
|
||||
app.use('/tools/oss_file_cabinet', (req, res, next) => {
|
||||
const forceGuid = isOssFileCabinetForceGuid()
|
||||
if (hasOssFileCabinetAuth(req)) return next()
|
||||
const isHandshake = req.method === 'GET' && (req.path === '/' || req.path === '' || req.path === '/index.html')
|
||||
const guidKey = getOssFileCabinetGuidConfig().key
|
||||
const hasGuidInput = isHandshake && req && req.query && Object.prototype.hasOwnProperty.call(req.query, guidKey)
|
||||
if (isHandshake && hasValidOssFileCabinetGuid(req)) {
|
||||
const maxAgeOfc = getOssFileCabinetMaxAge()
|
||||
const cookieName = getOssFileCabinetCookieName()
|
||||
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
|
||||
return res.redirect('/tools/oss_file_cabinet/index.html')
|
||||
}
|
||||
if (hasGuidInput) return res.status(401).send('未授权')
|
||||
if (isHandshake && String(req.query.token || '')) {
|
||||
const payload = verifyJwtWithKeys(String(req.query.token), jwkKeys(readOssFileCabinetJwk()))
|
||||
if (payload) {
|
||||
const iss = String(payload.iss || '')
|
||||
const navIss = getNavIssFromFlags()
|
||||
if (iss === navIss && !audMatch(payload, 'Tools-oss_file_cabinet')) return res.status(401).send('未授权')
|
||||
const maxAgeOfc = getOssFileCabinetMaxAge()
|
||||
const cookieName = getOssFileCabinetCookieName()
|
||||
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
|
||||
return res.redirect('/tools/oss_file_cabinet/index.html')
|
||||
}
|
||||
}
|
||||
if (isHandshake && forceGuid) return res.status(401).send('未授权')
|
||||
return res.status(401).send('未授权')
|
||||
})
|
||||
app.use('/api/oss_file_cabinet', (req, res, next) => {
|
||||
if (req.path.startsWith('/share/access/')) return next()
|
||||
if (hasOssFileCabinetAuth(req)) return next()
|
||||
return res.status(401).json({ ok: false, error: '未授权' })
|
||||
})
|
||||
|
||||
const WEEKLY_AUTH_COOKIE = 'weekly_gate'
|
||||
const readWeeklyJwk = () => {
|
||||
try {
|
||||
@@ -5842,6 +5986,8 @@ expense.bindRoutes(app)
|
||||
investmentLedger.bindRoutes(app)
|
||||
styleCheck.bindRoutes(app)
|
||||
globalNews.bindRoutes(app)
|
||||
dataGateway.bindRoutes(app)
|
||||
ossFileCabinet.bindRoutes(app)
|
||||
|
||||
const marketsCfgAtBoot = getMarketsCfg()
|
||||
const currentPort = Number(process.env.PORT || '8976') || 8976
|
||||
|
||||
Reference in New Issue
Block a user