feat: 添加安全中间件、优化限流器与API密钥验证
1. 新增安全响应头中间件强化请求安全性 2. 使用恒定时间比较修复API密钥验证时序漏洞 3. 新增限流器条目上限配置与自动清理逻辑 4. 优化CORS日志与客户端IP获取逻辑 5. 升级Go构建环境与基础镜像版本 6. 新增非root用户运行容器增强安全性
This commit is contained in:
+3
-6
@@ -96,16 +96,13 @@ func CORS(next http.Handler) http.Handler {
|
||||
} else if !strings.Contains(vary, "Origin") {
|
||||
w.Header().Set("Vary", vary+", Origin")
|
||||
}
|
||||
} else {
|
||||
log.Printf("CORS拦截: 来源=%q 路径=%s 方法=%s 客户端=%s",
|
||||
origin, r.URL.Path, r.Method, GetClientIP(r))
|
||||
}
|
||||
}
|
||||
|
||||
if r.Method == http.MethodOptions {
|
||||
if origin != "" {
|
||||
if _, matched := matchOrigin(origin); !matched {
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
return
|
||||
}
|
||||
}
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
return
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user