- 新增 server/rate-limit.ts:进程内固定窗口限流器,无数据库写入 - server/app.ts 注册全局 preHandler,仅作用于 /api/*,超限返回 429 与 Retry-After - 提取 isApiPath 统一 onSend、preHandler 与 404 的路径判断 - 更新任务冲突判定改用 ACTIVE_UPDATE_CONFLICT_SQL,staged/download 产物不再阻塞新任务 - cancelUpdateJob 调用补上 await,避免结果恒为 pending Promise - server/cli/update.ts 增加特权工作区所有权校验与暂存路径重建逻辑 - 新增 tests/rate-limit.test.ts 与 tests/update-apply-staging.test.ts
36 lines
1.8 KiB
Bash
36 lines
1.8 KiB
Bash
TALLYNOTE_HOST=127.0.0.1
|
|
TALLYNOTE_PORT=3000
|
|
TALLYNOTE_DATA_DIR=/var/lib/tallynote
|
|
TALLYNOTE_INSTALL_PREFIX=/opt/tallynote
|
|
TALLYNOTE_CONFIG_DIR=/etc/tallynote
|
|
TALLYNOTE_PUBLIC_ORIGIN=http://127.0.0.1:3000
|
|
TALLYNOTE_COOKIE_SECURE=false
|
|
TALLYNOTE_ALLOW_INSECURE_HTTP=false
|
|
TALLYNOTE_TIMEZONE=Asia/Shanghai
|
|
TALLYNOTE_UPDATE_STRATEGY=systemd
|
|
TALLYNOTE_UPDATE_METADATA_URL=https://git.awaioi.com/api/v1/repos/awaioi/TallyNote/releases/latest
|
|
TALLYNOTE_UPDATE_ALLOWED_HOSTS=git.awaioi.com
|
|
TALLYNOTE_UPDATE_TIMEOUT_SECONDS=30
|
|
TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=false
|
|
TALLYNOTE_UPDATE_CHECK_COOLDOWN_SECONDS=60
|
|
TALLYNOTE_UPDATE_DOWNLOAD_COOLDOWN_SECONDS=15
|
|
TALLYNOTE_UPDATE_APPLY_COOLDOWN_SECONDS=15
|
|
# Optional: configure a root-managed Ed25519 public key and set
|
|
# TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=true to require detached signatures.
|
|
# TALLYNOTE_UPDATE_PUBLIC_KEY_FILE=/etc/tallynote/update-signing-key.pub
|
|
|
|
# Reverse proxy trust. Leave this empty (or false) when TallyNote is reached
|
|
# directly. When the service runs behind a reverse proxy, set the exact number
|
|
# of proxy hops that terminate the client connection (a single nginx or caddy
|
|
# layer uses 1). Without it every request appears to come from the proxy
|
|
# address, so per-IP login lockouts degrade into a single shared global limit
|
|
# and the API rate limiter below counts all clients as one. `true` is rejected
|
|
# in production because it would let a client spoof its address.
|
|
# TALLYNOTE_TRUST_PROXY=1
|
|
|
|
# Global API rate limit, per client address, in requests per minute. This is a
|
|
# coarse anti-flood backstop for /api/* only; the login lockout, dangerous
|
|
# operation confirmation and update cooldowns remain stricter and separate.
|
|
# Defaults to 600 when unset, which is sufficient for normal browser use.
|
|
# TALLYNOTE_RATE_LIMIT_PER_MINUTE=600
|