diff --git a/- 副本.gitignore.2026-06-11 b/- 副本.gitignore.2026-06-11 new file mode 100644 index 0000000..0361921 --- /dev/null +++ b/- 副本.gitignore.2026-06-11 @@ -0,0 +1,71 @@ +# ===== 开发依赖 ===== +node_modules/ + +# ===== Windows 独有 ===== +winform/ +.DS_Store +Thumbs.db +desktop.ini + +# ===== 运行时数据(服务器重新生成)===== +data/ +logs/ +temp/ +.dbg/ +exports/ +backups/ +Toolbox-Weekly-Backup/ + +# ===== 前端大文件/素材(服务器不需要)===== +public/images/korean_references/ +public/images/zhihu/ +public/images/wave_references/ +public/images/x_fashion/ +public/images/style_check_images/ +public/home-bg/ +public/tools/apple_watch/apple_health_export/ +public/download_files/ + +# ===== 上传文件 ===== +uploads/ + +# ===== 脚本 ===== +scripts/ + +# ===== 本地凭证(含密码/密钥,不上传)===== +*.env.local +config/ +public/tools/markets/auth_config.json + +# ===== SSL 证书(服务器另有自己的)===== +umersoft.com_OV_SSL/ + +# ===== 调试/临时文件 ===== +*.md +*.txt +cookies.txt +_fix_*.js +_verify*.js +_verify2*.js +check_*.js +debug-*.md +example_auto_*.js +get_cookie_*.js +OSS权限.txt +.tmp_db_path.js +tmp_*.js +reproduce_issue.js +verify_db*.js +~\$*.docx + +# ===== IIS/构建配置(服务器不需要)===== +web.config +webpack.config.js +install_service_8977.bat +uninstall_service_8977.bat + +# ===== 杂项 ===== +.vscode/ +query +service/ +/tools/ \ No newline at end of file diff --git a/.gitignore b/.gitignore index 0361921..3180a2d 100644 --- a/.gitignore +++ b/.gitignore @@ -33,6 +33,15 @@ uploads/ scripts/ # ===== 本地凭证(含密码/密钥,不上传)===== +# +# ★ 规则:所有密码、密钥、Token、用户名等高危内容, +# 一律放在 ~/Toolbox_local_creds.env.local 中, +# 禁止硬编码在源码里。 +# env.local 已被本规则排除,config/ 目录同理。 +# +# 使用姿势:在 index.js 入口自动加载 ~/Toolbox_local_creds.env.local +# 到 process.env,各模块通过 process.env.XXX 读取。 +# *.env.local config/ public/tools/markets/auth_config.json diff --git a/src/server/index.js b/src/server/index.js index 0ab9e50..434621e 100644 --- a/src/server/index.js +++ b/src/server/index.js @@ -7,7 +7,9 @@ const Database = require('better-sqlite3') const crypto = require('crypto') // ===== 从 ~/Toolbox_local_creds.env.local 加载变量到 process.env ===== -// 所有模块的 process.env.XXX fallback 依赖此加载器 +// ★ 规则:所有密码、密钥、Token、用户名等高危内容,禁止硬编码在源码里。 +// 一律放在 ~/Toolbox_local_creds.env.local 中,在此处自动加载到 process.env +// 各模块通过 process.env.XXX 读取,不要直接 import 或 require 凭证。 // 优先级:已存在的 process.env > env 文件 > 模块内 '' fallback try { const os = require('os')