VUL-001 (中): aac/flac 响应 Content-Type 与真实数据不一致

controller.tts.go:contentTypeFor 对 aac/flac 返回 audio/aac/flac,
  但 adapter/volcano/synthesis.go 在上游降级时仅修改 opts.Format,
  finalFormat 仍保留 clientFormat,导致响应头与字节流不符。
  修复:finalFormat 改为反映真实输出格式(非 wav 时取 opts.Format),
  客户端按 AAC/FLAC 解码 MP3 流的失败场景消除。

VUL-004 (高): .env 凭据泄露
  README 引导用户 cp .env.example .env 填密钥,但 .gitignore
  未忽略 .env,任何 git add . 都会把含 BYTEDANCE_TTS_API_KEY
  的文件提交进 git 历史,不可逆。
  修复:
  - .gitignore 新增 Secrets section,拦截 .env 与 .env.* 变体,
    保留 .env.example 作为模板追踪
  - .dockerignore 升级为同名规则模式,覆盖未来 .env.local /
    .env.production 等变体,保证 git 与 docker 两通道一致

详见 VULNERABILITY_REPORT.md
"
This commit is contained in:
sun
2026-08-25 23:09:47 +08:00
parent 78c72004bf
commit 72d0d6a3a9
3 changed files with 16 additions and 3 deletions
+2 -1
View File
@@ -1,7 +1,8 @@
*.exe
*.md
.env
.env.example
.env.*
!.env.example
.git
.gitignore
tts_api_architecture.html
+7 -2
View File
@@ -1,4 +1,4 @@
# Go build cache
# Go build cache
.gocache/
*.exe
*.test
@@ -11,4 +11,9 @@
Thumbs.db
# Logs
*.log
*.log
# Secrets (do NOT commit local .env files; keep .env.example tracked as template)
.env
.env.*
!.env.example
+7
View File
@@ -116,7 +116,14 @@ func Synthesis(
duration := time.Since(started)
finalData := parsed.AudioData
// finalFormat 反映真实输出格式(用于 controller 写 Content-Type):
// - wav 走 pcm 上游 + 本地拼头,对外仍是 wav
// - aac/flac 在上方已被上游降级为 mp3,真实输出也是 mp3
// - 其余与 clientFormat 一致
finalFormat := clientFormat
if clientFormat != "wav" {
finalFormat = opts.Format
}
sampleRate := opts.SampleRate
if clientFormat == "wav" {
wav, wrapErr := WrapWAVHeader(parsed.AudioData, opts.SampleRate)