fix: allow reverse proxy login
TallyNote release / linux-x64 (push) Successful in 6m56s

This commit is contained in:
Qiufeng
2026-09-03 15:27:10 +08:00
parent 36c2ed1361
commit 4f9629b089
9 changed files with 6 additions and 49 deletions
-17
View File
@@ -43,21 +43,6 @@ function csvEnv(name: string): string[] {
.filter(Boolean);
}
function originListEnv(name: string, primary: string): string[] {
const values = [primary, ...csvEnv(name)];
const origins = new Set<string>();
for (const value of values) {
try {
const parsed = new URL(value);
if (!["http:", "https:"].includes(parsed.protocol) || parsed.username || parsed.password || parsed.pathname !== "/" && parsed.pathname !== "" || parsed.search || parsed.hash) throw new Error();
origins.add(parsed.origin);
} catch {
throw new Error(`${name} 必须是逗号分隔的 HTTP(S) Origin(不含路径)`);
}
}
return [...origins];
}
function updatePublicKeyEnv(): string | undefined {
const inline = process.env.TALLYNOTE_UPDATE_PUBLIC_KEY?.trim();
const file = process.env.TALLYNOTE_UPDATE_PUBLIC_KEY_FILE?.trim();
@@ -113,7 +98,6 @@ export function loadConfig() {
throw new Error("TALLYNOTE_PUBLIC_ORIGIN 不能使用通配监听地址,请填写服务器 IP 或域名");
}
const localOrigin = ["127.0.0.1", "localhost", "::1"].includes(publicHost);
const allowedOrigins = originListEnv("TALLYNOTE_ALLOWED_ORIGINS", parsedOrigin.origin);
const appVersion = (() => {
try {
const packageJson = JSON.parse(readFileSync(path.join(projectRoot, "package.json"), "utf8")) as { version?: unknown };
@@ -143,7 +127,6 @@ export function loadConfig() {
host,
port,
publicOrigin: parsedOrigin.origin,
allowedOrigins,
timezone,
trustProxy: trustProxyEnv(),
cookieSecure,