feat: 添加安全中间件、优化限流器与API密钥验证

1. 新增安全响应头中间件强化请求安全性
2. 使用恒定时间比较修复API密钥验证时序漏洞
3. 新增限流器条目上限配置与自动清理逻辑
4. 优化CORS日志与客户端IP获取逻辑
5. 升级Go构建环境与基础镜像版本
6. 新增非root用户运行容器增强安全性
This commit is contained in:
sun
2026-05-24 15:33:27 +08:00
parent 9c35f780db
commit 9b2a1d1531
8 changed files with 53 additions and 13 deletions
+16 -2
View File
@@ -1,6 +1,7 @@
package middleware
import (
"log"
"net"
"net/http"
"strings"
@@ -77,6 +78,16 @@ func (rl *RateLimiter) cleanup() {
rl.requests[k] = valid
}
}
if len(rl.requests) > common.MaxRateLimiterEntries {
log.Printf("警告: 限流器条目数 %d 超过上限 %d,触发强制清理", len(rl.requests), common.MaxRateLimiterEntries)
for k := range rl.requests {
if len(rl.requests) <= common.MaxRateLimiterEntries/2 {
break
}
delete(rl.requests, k)
}
}
}
func GetClientIP(r *http.Request) string {
@@ -84,11 +95,14 @@ func GetClientIP(r *http.Request) string {
if xForwardedFor != "" {
ips := strings.Split(xForwardedFor, ",")
if len(ips) > 0 {
return strings.TrimSpace(ips[0])
ip := strings.TrimSpace(ips[0])
if ip != "" {
return ip
}
}
}
xRealIP := r.Header.Get("X-Real-IP")
xRealIP := strings.TrimSpace(r.Header.Get("X-Real-IP"))
if xRealIP != "" {
return xRealIP
}