优化一些安全问题。并且升级优化一些安全问题。并且升级界面 - #573
Open
holamian827-oss wants to merge 13 commits into
Open
holamian827-oss wants to merge 13 commits into
holamian827-oss wants to merge 13 commits into
Conversation
Updated the description meta tag to a shorter version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
硬编码 JWT 密钥已泄露 — mail-worker/wrangler-dev.toml:44、wrangler-test.toml:42
两处都写着 jwt_secret = "b7f29a1d-..."(同一个值),旁边还有真实 database_id。生产用的 wrangler.toml:12 是空占位勉强过关,但只要有人照着 dev/test
配置部署过,密钥就是公开的——HS256 用固定密钥,拿到就能伪造 token。
→ 删掉仓库里的值,改 wrangler secret put jwt_secret,并轮换。
邮件正文 XSS(我认为这是全项目最该改的一处)
index.html 被 jsjiami.com.v4 整份混淆(已确认,11KB 入口全是 Function(...) 构造)
它逼着你必须开 CSP unsafe-eval,一开正经 CSP 就白屏;入口无法 review/diff,是供应链投毒的典型指纹。混淆只该用在第三方库上,不该用在入口 HTML。→ 还原明文。
三个免鉴权端点太宽 — mail-worker/src/security/security.js:11-22 的白名单