fix: 修复在线更新暂存链路并增加全局 API 限流备底
- 新增 server/rate-limit.ts:进程内固定窗口限流器,无数据库写入 - server/app.ts 注册全局 preHandler,仅作用于 /api/*,超限返回 429 与 Retry-After - 提取 isApiPath 统一 onSend、preHandler 与 404 的路径判断 - 更新任务冲突判定改用 ACTIVE_UPDATE_CONFLICT_SQL,staged/download 产物不再阻塞新任务 - cancelUpdateJob 调用补上 await,避免结果恒为 pending Promise - server/cli/update.ts 增加特权工作区所有权校验与暂存路径重建逻辑 - 新增 tests/rate-limit.test.ts 与 tests/update-apply-staging.test.ts
This commit is contained in:
@@ -18,3 +18,18 @@ TALLYNOTE_UPDATE_APPLY_COOLDOWN_SECONDS=15
|
||||
# Optional: configure a root-managed Ed25519 public key and set
|
||||
# TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=true to require detached signatures.
|
||||
# TALLYNOTE_UPDATE_PUBLIC_KEY_FILE=/etc/tallynote/update-signing-key.pub
|
||||
|
||||
# Reverse proxy trust. Leave this empty (or false) when TallyNote is reached
|
||||
# directly. When the service runs behind a reverse proxy, set the exact number
|
||||
# of proxy hops that terminate the client connection (a single nginx or caddy
|
||||
# layer uses 1). Without it every request appears to come from the proxy
|
||||
# address, so per-IP login lockouts degrade into a single shared global limit
|
||||
# and the API rate limiter below counts all clients as one. `true` is rejected
|
||||
# in production because it would let a client spoof its address.
|
||||
# TALLYNOTE_TRUST_PROXY=1
|
||||
|
||||
# Global API rate limit, per client address, in requests per minute. This is a
|
||||
# coarse anti-flood backstop for /api/* only; the login lockout, dangerous
|
||||
# operation confirmation and update cooldowns remain stricter and separate.
|
||||
# Defaults to 600 when unset, which is sufficient for normal browser use.
|
||||
# TALLYNOTE_RATE_LIMIT_PER_MINUTE=600
|
||||
|
||||
Reference in New Issue
Block a user