sun
91b0c8acee
fix: VUL-005 修复日志注入(RequestURI 与上游错误体转义)
...
VUL-005 (低): 攻击者可在 HTTP 请求 URL 或上游错误响应中
注入 \n / \r 字符,伪造日志行干扰排障。无代码执行风险。
修复位置:
- middleware/logger.go: 访问日志中的 r.RequestURI 是未经
解析的原始请求行,客户端可控。转义 \n / \r 为字面字符
- adapter/volcano/synthesis.go: 上游非 200 响应体 (rawBody)
可能是攻击者控制的恶意内容,转义后再嵌入错误消息
2026-08-26 11:52:28 +08:00
sun
72d0d6a3a9
VUL-001 (中): aac/flac 响应 Content-Type 与真实数据不一致
...
controller.tts.go:contentTypeFor 对 aac/flac 返回 audio/aac/flac,
但 adapter/volcano/synthesis.go 在上游降级时仅修改 opts.Format,
finalFormat 仍保留 clientFormat,导致响应头与字节流不符。
修复:finalFormat 改为反映真实输出格式(非 wav 时取 opts.Format),
客户端按 AAC/FLAC 解码 MP3 流的失败场景消除。
VUL-004 (高): .env 凭据泄露
README 引导用户 cp .env.example .env 填密钥,但 .gitignore
未忽略 .env,任何 git add . 都会把含 BYTEDANCE_TTS_API_KEY
的文件提交进 git 历史,不可逆。
修复:
- .gitignore 新增 Secrets section,拦截 .env 与 .env.* 变体,
保留 .env.example 作为模板追踪
- .dockerignore 升级为同名规则模式,覆盖未来 .env.local /
.env.production 等变体,保证 git 与 docker 两通道一致
详见 VULNERABILITY_REPORT.md
"
2026-08-25 23:09:47 +08:00
sun
155fab6b4b
feat: add debug log control and optimize error response and cors log
...
- add DebugLog global variable controlled by BYTEDANCE_TTS_DEBUG env
- enable debug logs for cors, tts upstream, response parsing etc when debug mode is on
- update tts error response to use standardized json error format
- add dashboard and metrics path to cache-control exempt list
2026-08-15 19:03:37 +08:00