VUL-003 修复期间意外发现项目遗留一批死代码,本次一并清掉:
- middleware/ratelimit_middleware.go(37 行,物理删除)
文件内 RateLimit / ConcurrencyLimit 函数从 977e9cc 创建后
从未被引用,370a217 commit 用 ratelimit_instrumented.go
(带 metrics 埋点 + 路径过滤)取代了它。占用包体,清。
- middleware/auth.go:InitAPIKeys(6 行)
注释说"已在 setting.InitAuthConfig 中完成",无 op。
- middleware/cors.go:InitCORSConfig(6 行)
同上,setting.InitCORSConfig 已做实际工作。
- dto/tts.go:ByteDanceTTSConfig 类型(7 行)
完整的配置走 setting.TTSOptions + adapter/volcano.Options,
此类型从未被任何代码实例化。
- setting/config.go: var _ = dto.ByteDanceTTSConfig{} 占位(3 行)
配合上方类型删除,移除 dto import。
- controller/tts.go:resolveClientFormat
合并 if reqFmt == "" 与 default 分支(都返回
setting.TTSOptions.Format),2 行简化。
- common/constants.go: MaxResponseTimes / MaxErrors
定义后从未被任何文件引用。
- middleware/ratelimit_instrumented.go 顶部注释
移除对"原 ratelimit_middleware.go"的悬空引用,
改为描述本文件相对路由使用实现的两个增强点。
影响:
- 包体减少约 30 行
- 降低新人接手时的代码理解成本
- 零功能变更,24 个现有测试用例全过
46 lines
944 B
Go
46 lines
944 B
Go
package middleware
|
|
|
|
import (
|
|
"crypto/subtle"
|
|
"encoding/json"
|
|
"net/http"
|
|
"strings"
|
|
|
|
"github.com/volcano-tts/tts-api/setting"
|
|
)
|
|
|
|
func ValidateAPIKey(r *http.Request) bool {
|
|
if len(setting.Auth.APIKeys) == 0 {
|
|
return true
|
|
}
|
|
|
|
authHeader := r.Header.Get("Authorization")
|
|
if authHeader == "" {
|
|
return false
|
|
}
|
|
|
|
if !strings.HasPrefix(authHeader, "Bearer ") {
|
|
return false
|
|
}
|
|
|
|
token := strings.TrimPrefix(authHeader, "Bearer ")
|
|
for _, validKey := range setting.Auth.APIKeys {
|
|
if subtle.ConstantTimeCompare([]byte(token), []byte(validKey)) == 1 {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func SendJSONError(w http.ResponseWriter, statusCode int, message string, errType string, code string) {
|
|
w.Header().Set("Content-Type", "application/json")
|
|
w.WriteHeader(statusCode)
|
|
json.NewEncoder(w).Encode(map[string]interface{}{
|
|
"error": map[string]interface{}{
|
|
"message": message,
|
|
"type": errType,
|
|
"code": code,
|
|
},
|
|
})
|
|
}
|