fix: 安全加固(VUL-001~009)+ 构建版本注入 + 死代码清理 #2
@@ -15,8 +15,6 @@ const (
|
|||||||
MaxRequestBodySize = 1024 * 1024
|
MaxRequestBodySize = 1024 * 1024
|
||||||
RateLimitRequests = 100
|
RateLimitRequests = 100
|
||||||
RateLimitWindow = time.Minute
|
RateLimitWindow = time.Minute
|
||||||
MaxResponseTimes = 100
|
|
||||||
MaxErrors = 10
|
|
||||||
MaxConcurrentRequests = 10
|
MaxConcurrentRequests = 10
|
||||||
CleanupInterval = time.Hour
|
CleanupInterval = time.Hour
|
||||||
MaxModelNameLength = 64
|
MaxModelNameLength = 64
|
||||||
|
|||||||
@@ -46,9 +46,6 @@ func resolveClientFormat(reqFmt string) string {
|
|||||||
}
|
}
|
||||||
return strings.ToLower(reqFmt)
|
return strings.ToLower(reqFmt)
|
||||||
}
|
}
|
||||||
if reqFmt == "" {
|
|
||||||
return setting.TTSOptions.Format
|
|
||||||
}
|
|
||||||
return setting.TTSOptions.Format
|
return setting.TTSOptions.Format
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -58,15 +58,6 @@ type V3Usage struct {
|
|||||||
TextWords int `json:"text_words"`
|
TextWords int `json:"text_words"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// ByteDanceTTSConfig 是 setting 包的全局 TTS 配置,目前只承载鉴权 / URL / 超时;
|
|
||||||
// 完整的合成参数见 adapter/volcano.Options。
|
|
||||||
type ByteDanceTTSConfig struct {
|
|
||||||
ApiKey string
|
|
||||||
ResourceId string
|
|
||||||
URL string
|
|
||||||
Timeout time.Duration
|
|
||||||
}
|
|
||||||
|
|
||||||
// SynthesisResult 是火山适配器向 controller 返回的最终结果。
|
// SynthesisResult 是火山适配器向 controller 返回的最终结果。
|
||||||
// Format 与 AudioData 的实际编码一致;controller 据此设置响应 Content-Type。
|
// Format 与 AudioData 的实际编码一致;controller 据此设置响应 Content-Type。
|
||||||
type SynthesisResult struct {
|
type SynthesisResult struct {
|
||||||
|
|||||||
@@ -9,13 +9,6 @@ import (
|
|||||||
"github.com/volcano-tts/tts-api/setting"
|
"github.com/volcano-tts/tts-api/setting"
|
||||||
)
|
)
|
||||||
|
|
||||||
// InitAPIKeys 已在 setting.InitAuthConfig 中完成,这里保留为 no-op 以维持现有调用顺序。
|
|
||||||
// 实际鉴权逻辑直接读 setting.Auth.APIKeys。
|
|
||||||
func InitAPIKeys() {
|
|
||||||
// 配置由 setting 包统一加载,日志也由 setting.LogStartupSummary 输出。
|
|
||||||
_ = setting.Auth
|
|
||||||
}
|
|
||||||
|
|
||||||
func ValidateAPIKey(r *http.Request) bool {
|
func ValidateAPIKey(r *http.Request) bool {
|
||||||
if len(setting.Auth.APIKeys) == 0 {
|
if len(setting.Auth.APIKeys) == 0 {
|
||||||
return true
|
return true
|
||||||
|
|||||||
@@ -13,13 +13,6 @@ var (
|
|||||||
corsMaxAgeHeader = "86400"
|
corsMaxAgeHeader = "86400"
|
||||||
)
|
)
|
||||||
|
|
||||||
// InitCORSConfig 已在 setting.InitCORSConfig 中完成,这里保留为 no-op 以维持现有调用顺序。
|
|
||||||
// 实际 CORS 匹配逻辑直接读 setting.CORS.Origins / setting.CORS.AllowAll。
|
|
||||||
func InitCORSConfig() {
|
|
||||||
// 配置由 setting 包统一加载,日志也由 setting.LogStartupSummary 输出。
|
|
||||||
_ = setting.CORS
|
|
||||||
}
|
|
||||||
|
|
||||||
func isValidOrigin(origin string) bool {
|
func isValidOrigin(origin string) bool {
|
||||||
if origin == "" || origin == "null" || origin == "nil" {
|
if origin == "" || origin == "null" || origin == "nil" {
|
||||||
return false
|
return false
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
package middleware
|
package middleware
|
||||||
|
|
||||||
// 本文件提供带 metrics 埋点的限流 / 并发中间件版本;
|
// 本文件提供带 metrics 埋点的限流 / 并发中间件版本。
|
||||||
// 由于原 ratelimit_middleware.go 在本仓库的云盘同步下被永久占用,
|
// 相比 router 实际使用的实现,本版本额外做了:
|
||||||
// 这里用独立实现覆盖路由使用入口,旧实现保留为未引用代码。
|
// - 加 metrics 埋点(限流拒绝 / 并发拒绝计数)
|
||||||
//
|
// - 仅对 /v1/ 下的业务请求生效,监控路径(/health /metrics /dashboard)不消耗配额
|
||||||
// 行为与原 ratelimit_middleware.go 完全一致,只是多了 metrics 调用。
|
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"log"
|
"log"
|
||||||
@@ -14,7 +13,7 @@ import (
|
|||||||
"github.com/volcano-tts/tts-api/metrics"
|
"github.com/volcano-tts/tts-api/metrics"
|
||||||
)
|
)
|
||||||
|
|
||||||
// RateLimitWithMetrics 是 middleware.RateLimit 的可埋点版本。
|
// RateLimitWithMetrics 是限流中间件,带埋点 + 路径过滤。
|
||||||
func RateLimitWithMetrics(next http.Handler) http.Handler {
|
func RateLimitWithMetrics(next http.Handler) http.Handler {
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
// 仅对 /v1/ 下的业务请求限流,/health /metrics /dashboard 等监控路径不限流
|
// 仅对 /v1/ 下的业务请求限流,/health /metrics /dashboard 等监控路径不限流
|
||||||
@@ -32,7 +31,7 @@ func RateLimitWithMetrics(next http.Handler) http.Handler {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// ConcurrencyLimitWithMetrics 是 middleware.ConcurrencyLimit 的可埋点版本。
|
// ConcurrencyLimitWithMetrics 是并发控制中间件,带埋点 + 路径过滤。
|
||||||
func ConcurrencyLimitWithMetrics(next http.Handler) http.Handler {
|
func ConcurrencyLimitWithMetrics(next http.Handler) http.Handler {
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
// 仅对 /v1/ 下的业务请求统计并发和加锁,监控路径不占用并发槽位
|
// 仅对 /v1/ 下的业务请求统计并发和加锁,监控路径不占用并发槽位
|
||||||
|
|||||||
@@ -1,32 +0,0 @@
|
|||||||
package middleware
|
|
||||||
|
|
||||||
import (
|
|
||||||
"log"
|
|
||||||
"net/http"
|
|
||||||
)
|
|
||||||
|
|
||||||
func RateLimit(next http.Handler) http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
clientIP := GetClientIP(r)
|
|
||||||
if !GlobalRateLimiter.Allow(clientIP) {
|
|
||||||
log.Printf("警告: 已超过IP速率限制,拒绝请求 - 客户端IP: %s", clientIP)
|
|
||||||
SendJSONError(w, http.StatusTooManyRequests, "Rate limit exceeded. Please try again later.", "rate_limit_error", "rate_limit_exceeded")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
next.ServeHTTP(w, r)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func ConcurrencyLimit(next http.Handler) http.Handler {
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
select {
|
|
||||||
case ConcurrencySem <- struct{}{}:
|
|
||||||
defer func() { <-ConcurrencySem }()
|
|
||||||
next.ServeHTTP(w, r)
|
|
||||||
default:
|
|
||||||
log.Printf("警告: 已达到最大并发请求数限制,拒绝请求 - 客户端IP: %s", GetClientIP(r))
|
|
||||||
SendJSONError(w, http.StatusServiceUnavailable, "Server is busy, maximum concurrent requests reached. Please try again later.", "concurrency_limit_error", "max_concurrent_requests")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
@@ -10,7 +10,6 @@ import (
|
|||||||
|
|
||||||
"github.com/volcano-tts/tts-api/adapter/volcano"
|
"github.com/volcano-tts/tts-api/adapter/volcano"
|
||||||
"github.com/volcano-tts/tts-api/common"
|
"github.com/volcano-tts/tts-api/common"
|
||||||
"github.com/volcano-tts/tts-api/dto"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// 全部环境变量读取的单一入口:其它包不允许直接 os.Getenv,只读这里的全局 Config。
|
// 全部环境变量读取的单一入口:其它包不允许直接 os.Getenv,只读这里的全局 Config。
|
||||||
@@ -317,7 +316,3 @@ func CheckStaticFiles() {
|
|||||||
log.Println("警告: health.html 不存在,/dashboard 路由将返回 404")
|
log.Println("警告: health.html 不存在,/dashboard 路由将返回 404")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// 保留 dto.ByteDanceTTSConfig 引用避免 import 警告;
|
|
||||||
// 新代码不应再使用这个类型,设置已在 TTSOptions 中。
|
|
||||||
var _ = dto.ByteDanceTTSConfig{}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user