VUL-001 (中): aac/flac 响应 Content-Type 与真实数据不一致
controller.tts.go:contentTypeFor 对 aac/flac 返回 audio/aac/flac,
但 adapter/volcano/synthesis.go 在上游降级时仅修改 opts.Format,
finalFormat 仍保留 clientFormat,导致响应头与字节流不符。
修复:finalFormat 改为反映真实输出格式(非 wav 时取 opts.Format),
客户端按 AAC/FLAC 解码 MP3 流的失败场景消除。
VUL-004 (高): .env 凭据泄露
README 引导用户 cp .env.example .env 填密钥,但 .gitignore
未忽略 .env,任何 git add . 都会把含 BYTEDANCE_TTS_API_KEY
的文件提交进 git 历史,不可逆。
修复:
- .gitignore 新增 Secrets section,拦截 .env 与 .env.* 变体,
保留 .env.example 作为模板追踪
- .dockerignore 升级为同名规则模式,覆盖未来 .env.local /
.env.production 等变体,保证 git 与 docker 两通道一致
详见 VULNERABILITY_REPORT.md
"
This commit is contained in:
+2
-1
@@ -1,7 +1,8 @@
|
||||
*.exe
|
||||
*.md
|
||||
.env
|
||||
.env.example
|
||||
.env.*
|
||||
!.env.example
|
||||
.git
|
||||
.gitignore
|
||||
tts_api_architecture.html
|
||||
|
||||
+7
-2
@@ -1,4 +1,4 @@
|
||||
# Go build cache
|
||||
# Go build cache
|
||||
.gocache/
|
||||
*.exe
|
||||
*.test
|
||||
@@ -11,4 +11,9 @@
|
||||
Thumbs.db
|
||||
|
||||
# Logs
|
||||
*.log
|
||||
*.log
|
||||
|
||||
# Secrets (do NOT commit local .env files; keep .env.example tracked as template)
|
||||
.env
|
||||
.env.*
|
||||
!.env.example
|
||||
@@ -116,7 +116,14 @@ func Synthesis(
|
||||
duration := time.Since(started)
|
||||
|
||||
finalData := parsed.AudioData
|
||||
// finalFormat 反映真实输出格式(用于 controller 写 Content-Type):
|
||||
// - wav 走 pcm 上游 + 本地拼头,对外仍是 wav
|
||||
// - aac/flac 在上方已被上游降级为 mp3,真实输出也是 mp3
|
||||
// - 其余与 clientFormat 一致
|
||||
finalFormat := clientFormat
|
||||
if clientFormat != "wav" {
|
||||
finalFormat = opts.Format
|
||||
}
|
||||
sampleRate := opts.SampleRate
|
||||
if clientFormat == "wav" {
|
||||
wav, wrapErr := WrapWAVHeader(parsed.AudioData, opts.SampleRate)
|
||||
|
||||
Reference in New Issue
Block a user