chore: add and update gitignore rules for project files

add a comprehensive gitignore file to exclude unnecessary files like dependencies, runtime data, uploads, local configs and debug temporary files
This commit is contained in:
yangxiangyuan
2026-06-12 09:48:21 +08:00
parent c223c79b36
commit d3856cb52a
60 changed files with 13144 additions and 525 deletions
+147 -1
View File
@@ -7,7 +7,9 @@ const Database = require('better-sqlite3')
const crypto = require('crypto')
// ===== 从 ~/Toolbox_local_creds.env.local 加载变量到 process.env =====
// 所有模块的 process.env.XXX fallback 依赖此加载器
// ★ 规则:所有密码、密钥、Token、用户名等高危内容,禁止硬编码在源码里。
// 一律放在 ~/Toolbox_local_creds.env.local 中,在此处自动加载到 process.env
// 各模块通过 process.env.XXX 读取,不要直接 import 或 require 凭证。
// 优先级:已存在的 process.env > env 文件 > 模块内 '' fallback
try {
const os = require('os')
@@ -76,6 +78,8 @@ const plantHome = require('./plant_home')
const globalNews = require('./global_news')
const boxBackup = require('./box_backup')
const yuanzhupai = require('./yuanzhupai')
const dataGateway = require('./data_gateway')
const ossFileCabinet = require('./oss_file_cabinet')
yuanzhupai.initDb()
const app = express()
@@ -1335,6 +1339,7 @@ const mapSystemIdToUrl = (systemId) => {
'FitnessDiary': '/tools/fitness_diary',
'Tools-doc_cloud_keeper': '/tools/doc_cloud_keeper',
'Tools-yuanzhupai': '/tools/yuanzhupai',
'Tools-oss_file_cabinet': '/tools/oss_file_cabinet',
'Tools-plant_home': '/tools/plant_home',
'Tools-apple_watch': '/tools/apple_watch',
'Tools-private_clipboard': '/tools/private_clipboard',
@@ -2078,6 +2083,145 @@ app.use('/api/private_clipboard', (req, res, next) => {
return res.status(503).json({ ok: false, error: 'service_not_ready' })
})
const OSS_FILE_CABINET_AUTH_COOKIE = 'oss_file_cabinet_gate'
const readOssFileCabinetAuthConfig = () => {
try {
const p = path.join(process.cwd(), 'public', 'tools', 'oss_file_cabinet', 'auth_config.json')
if (fs.existsSync(p)) {
const cfg = JSON.parse(fs.readFileSync(p, 'utf-8'))
if (cfg && typeof cfg === 'object') return cfg
}
} catch {}
return {}
}
const readOssFileCabinetJwk = () => {
try {
const p = path.join(process.cwd(), 'config', 'oss_file_cabinet.jwk.json')
if (fs.existsSync(p)) return JSON.parse(fs.readFileSync(p, 'utf-8'))
} catch {}
return { kty: 'RSA', n: '', e: '' }
}
const getOssFileCabinetCookieName = () => {
try {
const cfg = readOssFileCabinetAuthConfig()
const n = String(cfg.cookieName || '')
if (n) return n
} catch {}
return OSS_FILE_CABINET_AUTH_COOKIE
}
const getOssFileCabinetMaxAge = () => {
try {
const cfg = readOssFileCabinetAuthConfig()
const days = Number(cfg.max_age_days || 0)
if (Number.isFinite(days) && days > 0) return Math.min(days, 365) * 24 * 3600 * 1000
} catch {}
return 30 * 24 * 3600 * 1000
}
const getOssFileCabinetGuidConfig = () => {
try {
const cfg = readOssFileCabinetAuthConfig()
const keyRaw = String(cfg.guidParam || cfg.guid_param || 'guid').trim()
const valueRaw = String(cfg.guidValue || cfg.guid_value || '').trim()
return { key: keyRaw || 'guid', value: valueRaw }
} catch { return { key: 'guid', value: '' } }
}
const hasValidOssFileCabinetGuid = (req) => {
try {
const cfg = readOssFileCabinetAuthConfig()
if (cfg.enable_auth === false) return false
const { key, value } = getOssFileCabinetGuidConfig()
if (!value) return false
const q = req && req.query ? req.query : {}
const raw = q[key]
if (raw === undefined || raw === null) return false
const incoming = Array.isArray(raw) ? String(raw[0] || '') : String(raw)
return incoming === value
} catch { return false }
}
const hasOssFileCabinetAuth = (req) => {
try {
const cfg = readOssFileCabinetAuthConfig()
if (cfg.enable_auth === false) return true
const cookies = parseCookie(req.headers.cookie || '')
const name = getOssFileCabinetCookieName()
return cookies[name] === '1'
} catch { return false }
}
const isOssFileCabinetForceGuid = () => {
try {
const cfg = readOssFileCabinetAuthConfig()
if (cfg.enable_auth === false) return false
if (Object.prototype.hasOwnProperty.call(cfg, 'requireGuid')) return !!cfg.requireGuid
if (Object.prototype.hasOwnProperty.call(cfg, 'require_guid')) return !!cfg.require_guid
return true
} catch { return true }
}
app.get('/tools/oss_file_cabinet', (req, res, next) => {
setNoCache(res)
try {
const forceGuid = isOssFileCabinetForceGuid()
if (hasOssFileCabinetAuth(req)) return next()
const guidKey = getOssFileCabinetGuidConfig().key
const hasGuidInput = req && req.query && Object.prototype.hasOwnProperty.call(req.query, guidKey)
if (hasValidOssFileCabinetGuid(req)) {
const maxAgeOfc = getOssFileCabinetMaxAge()
const cookieName = getOssFileCabinetCookieName()
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
return res.redirect('/tools/oss_file_cabinet/index.html')
}
if (hasGuidInput) return res.status(401).send('未授权')
const token = String(req.query.token || '')
if (!token) {
if (forceGuid) return res.status(401).send('未授权')
return next()
}
const payload = verifyJwtWithKeys(token, jwkKeys(readOssFileCabinetJwk()))
if (!payload) return res.status(401).send('未授权')
{
const iss = String(payload.iss || '')
const navIss = getNavIssFromFlags()
if (iss === navIss && !audMatch(payload, 'Tools-oss_file_cabinet')) return res.status(401).send('未授权')
}
const maxAgeOfc = getOssFileCabinetMaxAge()
const cookieName = getOssFileCabinetCookieName()
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
return res.redirect('/tools/oss_file_cabinet/index.html')
} catch { return res.status(401).send('未授权') }
})
app.use('/tools/oss_file_cabinet', (req, res, next) => {
const forceGuid = isOssFileCabinetForceGuid()
if (hasOssFileCabinetAuth(req)) return next()
const isHandshake = req.method === 'GET' && (req.path === '/' || req.path === '' || req.path === '/index.html')
const guidKey = getOssFileCabinetGuidConfig().key
const hasGuidInput = isHandshake && req && req.query && Object.prototype.hasOwnProperty.call(req.query, guidKey)
if (isHandshake && hasValidOssFileCabinetGuid(req)) {
const maxAgeOfc = getOssFileCabinetMaxAge()
const cookieName = getOssFileCabinetCookieName()
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
return res.redirect('/tools/oss_file_cabinet/index.html')
}
if (hasGuidInput) return res.status(401).send('未授权')
if (isHandshake && String(req.query.token || '')) {
const payload = verifyJwtWithKeys(String(req.query.token), jwkKeys(readOssFileCabinetJwk()))
if (payload) {
const iss = String(payload.iss || '')
const navIss = getNavIssFromFlags()
if (iss === navIss && !audMatch(payload, 'Tools-oss_file_cabinet')) return res.status(401).send('未授权')
const maxAgeOfc = getOssFileCabinetMaxAge()
const cookieName = getOssFileCabinetCookieName()
res.cookie(cookieName, '1', { httpOnly: true, sameSite: 'lax', maxAge: maxAgeOfc, path: '/' })
return res.redirect('/tools/oss_file_cabinet/index.html')
}
}
if (isHandshake && forceGuid) return res.status(401).send('未授权')
return res.status(401).send('未授权')
})
app.use('/api/oss_file_cabinet', (req, res, next) => {
if (req.path.startsWith('/share/access/')) return next()
if (hasOssFileCabinetAuth(req)) return next()
return res.status(401).json({ ok: false, error: '未授权' })
})
const WEEKLY_AUTH_COOKIE = 'weekly_gate'
const readWeeklyJwk = () => {
try {
@@ -5842,6 +5986,8 @@ expense.bindRoutes(app)
investmentLedger.bindRoutes(app)
styleCheck.bindRoutes(app)
globalNews.bindRoutes(app)
dataGateway.bindRoutes(app)
ossFileCabinet.bindRoutes(app)
const marketsCfgAtBoot = getMarketsCfg()
const currentPort = Number(process.env.PORT || '8976') || 8976