VUL-003 修复期间意外发现项目遗留一批死代码,本次一并清掉:
- middleware/ratelimit_middleware.go(37 行,物理删除)
文件内 RateLimit / ConcurrencyLimit 函数从 977e9cc 创建后
从未被引用,370a217 commit 用 ratelimit_instrumented.go
(带 metrics 埋点 + 路径过滤)取代了它。占用包体,清。
- middleware/auth.go:InitAPIKeys(6 行)
注释说"已在 setting.InitAuthConfig 中完成",无 op。
- middleware/cors.go:InitCORSConfig(6 行)
同上,setting.InitCORSConfig 已做实际工作。
- dto/tts.go:ByteDanceTTSConfig 类型(7 行)
完整的配置走 setting.TTSOptions + adapter/volcano.Options,
此类型从未被任何代码实例化。
- setting/config.go: var _ = dto.ByteDanceTTSConfig{} 占位(3 行)
配合上方类型删除,移除 dto import。
- controller/tts.go:resolveClientFormat
合并 if reqFmt == "" 与 default 分支(都返回
setting.TTSOptions.Format),2 行简化。
- common/constants.go: MaxResponseTimes / MaxErrors
定义后从未被任何文件引用。
- middleware/ratelimit_instrumented.go 顶部注释
移除对"原 ratelimit_middleware.go"的悬空引用,
改为描述本文件相对路由使用实现的两个增强点。
影响:
- 包体减少约 30 行
- 降低新人接手时的代码理解成本
- 零功能变更,24 个现有测试用例全过
58 lines
2.0 KiB
Go
58 lines
2.0 KiB
Go
package middleware
|
|
|
|
// 本文件提供带 metrics 埋点的限流 / 并发中间件版本。
|
|
// 相比 router 实际使用的实现,本版本额外做了:
|
|
// - 加 metrics 埋点(限流拒绝 / 并发拒绝计数)
|
|
// - 仅对 /v1/ 下的业务请求生效,监控路径(/health /metrics /dashboard)不消耗配额
|
|
|
|
import (
|
|
"log"
|
|
"net/http"
|
|
"strings"
|
|
|
|
"github.com/volcano-tts/tts-api/metrics"
|
|
)
|
|
|
|
// RateLimitWithMetrics 是限流中间件,带埋点 + 路径过滤。
|
|
func RateLimitWithMetrics(next http.Handler) http.Handler {
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
// 仅对 /v1/ 下的业务请求限流,/health /metrics /dashboard 等监控路径不限流
|
|
if !strings.HasPrefix(r.URL.Path, "/v1/") {
|
|
next.ServeHTTP(w, r)
|
|
return
|
|
}
|
|
clientIP := GetClientIP(r)
|
|
if !GlobalRateLimiter.Allow(clientIP) {
|
|
log.Printf("警告: 已超过IP速率限制,拒绝请求 - 客户端IP: %s", clientIP)
|
|
SendJSONError(w, http.StatusTooManyRequests, "Rate limit exceeded. Please try again later.", "rate_limit_error", "rate_limit_exceeded")
|
|
return
|
|
}
|
|
next.ServeHTTP(w, r)
|
|
})
|
|
}
|
|
|
|
// ConcurrencyLimitWithMetrics 是并发控制中间件,带埋点 + 路径过滤。
|
|
func ConcurrencyLimitWithMetrics(next http.Handler) http.Handler {
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
// 仅对 /v1/ 下的业务请求统计并发和加锁,监控路径不占用并发槽位
|
|
if !strings.HasPrefix(r.URL.Path, "/v1/") {
|
|
next.ServeHTTP(w, r)
|
|
return
|
|
}
|
|
select {
|
|
case ConcurrencySem <- struct{}{}:
|
|
metrics.ConcurrencyActive.Inc(nil)
|
|
defer func() {
|
|
<-ConcurrencySem
|
|
metrics.ConcurrencyActive.Dec(nil)
|
|
}()
|
|
next.ServeHTTP(w, r)
|
|
default:
|
|
metrics.ConcurrencyRejected.Inc(nil)
|
|
log.Printf("警告: 已达到最大并发请求数限制,拒绝请求 - 客户端IP: %s", GetClientIP(r))
|
|
SendJSONError(w, http.StatusServiceUnavailable, "Server is busy, maximum concurrent requests reached. Please try again later.", "concurrency_limit_error", "max_concurrent_requests")
|
|
return
|
|
}
|
|
})
|
|
}
|