fix: 修复在线更新暂存链路并增加全局 API 限流备底

- 新增 server/rate-limit.ts:进程内固定窗口限流器,无数据库写入
- server/app.ts 注册全局 preHandler,仅作用于 /api/*,超限返回 429 与 Retry-After
- 提取 isApiPath 统一 onSend、preHandler 与 404 的路径判断
- 更新任务冲突判定改用 ACTIVE_UPDATE_CONFLICT_SQL,staged/download 产物不再阻塞新任务
- cancelUpdateJob 调用补上 await,避免结果恒为 pending Promise
- server/cli/update.ts 增加特权工作区所有权校验与暂存路径重建逻辑
- 新增 tests/rate-limit.test.ts 与 tests/update-apply-staging.test.ts
This commit is contained in:
Qiufeng
2026-09-17 13:12:20 +08:00
parent 5afcd98ebd
commit ae8966baf6
12 changed files with 1145 additions and 71 deletions
+15
View File
@@ -18,3 +18,18 @@ TALLYNOTE_UPDATE_APPLY_COOLDOWN_SECONDS=15
# Optional: configure a root-managed Ed25519 public key and set
# TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=true to require detached signatures.
# TALLYNOTE_UPDATE_PUBLIC_KEY_FILE=/etc/tallynote/update-signing-key.pub
# Reverse proxy trust. Leave this empty (or false) when TallyNote is reached
# directly. When the service runs behind a reverse proxy, set the exact number
# of proxy hops that terminate the client connection (a single nginx or caddy
# layer uses 1). Without it every request appears to come from the proxy
# address, so per-IP login lockouts degrade into a single shared global limit
# and the API rate limiter below counts all clients as one. `true` is rejected
# in production because it would let a client spoof its address.
# TALLYNOTE_TRUST_PROXY=1
# Global API rate limit, per client address, in requests per minute. This is a
# coarse anti-flood backstop for /api/* only; the login lockout, dangerous
# operation confirmation and update cooldowns remain stricter and separate.
# Defaults to 600 when unset, which is sufficient for normal browser use.
# TALLYNOTE_RATE_LIMIT_PER_MINUTE=600